Vulnerabilidades en Roxnor

89 resultados
Análisis Vexday

Roxnor apresenta um perfil de risco moderado com 17 vulnerabilidades catalogadas, sendo apenas 1 crítica e nenhuma sob exploração ativa documentada. A fraqueza dominante é falta de autorização (CWE-862), com 2 novos CVEs nos últimos 90 dias, indicando descobertas recentes mas sem urgência de resposta imediata.

CVE-2026-75971HIGHShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' NodesEPSS 0.6%CVE-2023-0689MEDIUMMetform Elementor Contact Form Builder <= 3.3.1 - Authenticated (Subscriber+) Information Disclosure via 'mf_first_name' shortcodeEPSS 0.6%CVE-2023-0708MEDIUMMetform Elementor Contact Form Builder <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via mf_first_name shortcodeEPSS 0.6%CVE-2026-32470CRITICALWordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-73993CRITICALWordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2023-0709MEDIUMMetform Elementor Contact Form Builder <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via mf_last_name shortcodeEPSS 0.6%CVE-2024-4266MEDIUMMetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticated Sensitive Information ExposureEPSS 0.5%CVE-2023-6582MEDIUMElementsKit Lite <= 3.0.3 - Unauthenticated Sensitive Information ExposureEPSS 0.5%CVE-2024-1585MEDIUMMetform Elementor Contact Form Builder <= 3.8.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2025-48302HIGHWordPress FundEngine Plugin <= 1.7.4 - Local File Inclusion VulnerabilityEPSS 0.5%CVE-2025-0968MEDIUMElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content FunctionEPSS 0.5%CVE-2024-21746MEDIUMWordPress Wp Ultimate Review plugin <= 2.3.6 - IP limit Bypass vulnerabilityEPSS 0.5%CVE-2024-2042MEDIUMElementsKit Elementor addons <= 3.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion WidgetEPSS 0.5%CVE-2024-8546MEDIUMElementsKit Elementor addons <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video WidgetEPSS 0.4%CVE-2024-1763MEDIUMWp Social Login and Register Social Counter <= 3.0.0 - Missing Authorization to Unauthenticated Social Login/Share Status UpdateEPSS 0.4%CVE-2024-33570MEDIUMWordPress MetForm plugin <= 3.8.3 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-6698HIGHFundEngine – Donation and Crowdfunding Platform <= 1.7.0 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.4%CVE-2025-14314HIGHWordPress PopupKit plugin <= 2.1.5 - SQL Injection vulnerabilityEPSS 0.4%CVE-2023-6525MEDIUMElementsKit Elementor addons <= 3.0.3 - Authenticated(Editor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2025-13192HIGHPopup builder with Gamification <= 2.2.0 - Unauthenticated SQL Injection via Multiple REST API EndpointsEPSS 0.4%