Vulnerabilidades en Smackcoders
23 resultadosAnálisis Vexday
Smackcoders apresenta 3 vulnerabilidades registradas, todas relacionadas a exposição de informações (CWE-200), sem casos críticos ou sob exploração ativa conhecida. Nenhuma vulnerabilidade foi publicada nos últimos 90 dias, indicando um panorama de risco estável e de menor urgência.
CVE-2024-43965HIGHWordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerabilityEPSS 2.0%CVE-2023-4142HIGHWP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code ExecutionEPSS 1.6%CVE-2023-4141HIGHWP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code ExecutionEPSS 1.6%CVE-2025-2008HIGHImport Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 1.2%CVE-2025-2007HIGHImport Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 1.2%CVE-2026-13353HIGHWP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' ParameterEPSS 1.1%CVE-2023-4140MEDIUMWP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege EscalationEPSS 0.8%CVE-2025-2332CRITICALExport All Posts, Products, Orders, Refunds & Users <= 2.13 - Unauthenticated PHP Object InjectionEPSS 0.8%CVE-2025-10057HIGHWP Import – Ultimate CSV XML Importer for WordPress 7.20 - 7.28 - Authenticated (Subscriber+) Remote Code Execution via Code InjectionEPSS 0.7%CVE-2025-9990HIGHWordPress Helpdesk Integration <= 5.8.10 - Unauthenticated Local File InclusionEPSS 0.7%CVE-2023-4139HIGHWP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory ListingEPSS 0.7%CVE-2025-10058HIGHWP Import – Ultimate CSV XML Importer for WordPress <= 7.27 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.6%CVE-2023-45066MEDIUMWordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2025-13145HIGHWP Import – Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP Object Injection via CSV ImportEPSS 0.5%CVE-2024-12315HIGHExport All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected DirectoryEPSS 0.5%CVE-2023-2487MEDIUMWordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2024-9364MEDIUMSendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log DeletionEPSS 0.4%CVE-2025-10040HIGHWP Import – Ultimate CSV XML Importer for WordPress <= 7.27 - Missing Authorization to Authenticated (Subscriber+) FTP/SFTP Credential ExposureEPSS 0.3%CVE-2025-14627MEDIUMWP Import – Ultimate CSV XML Importer for WordPress <= 7.35 - Authenticated (Contributor+) Server-Side Request Forgery via Bitly Shortlink BypassEPSS 0.3%CVE-2025-12732MEDIUMWP Import – Ultimate CSV XML Importer for WordPress <= 7.33 - Missing Authorization to Authenticated (Author+) Sensitive Information ExposureEPSS 0.3%