Vulnerabilidades en Unknown
5554 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2026-87918MEDIUMWPBot < 8.5.7 - Unauthenticated AI Provider API Abuse via Multiple AJAX ActionsEPSS 0.3%CVE-2026-82848MEDIUMMasteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment DisclosureEPSS 0.3%CVE-2026-82213MEDIUMNexi XPay Build 7.6.1 - 7.6.2 - Unauthenticated Saved Payment Token Disclosure via IDOREPSS 0.3%CVE-2026-14832MEDIUMShopSmart Loyalty for WooCommerce <= 1.0.0 - Unauthenticated Sensitive Information Disclosure via shopsmart_check_phoneEPSS 0.3%CVE-2026-14314MEDIUMPeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attachment Disclosure via IDOREPSS 0.3%CVE-2026-15240HIGHCustomer Switching for WooCommerce < 2.1.3 - Customer+ Privilege Escalation to Administrator via Insecure Operator ResolutionEPSS 0.3%CVE-2024-8857MEDIUMWordPress Auction <= 3.7 - Editor+ Stored XSSEPSS 0.3%CVE-2026-13700MEDIUMWooMS <= 9.14 - Unauthenticated Server-Side Request Forgery and Sensitive Information DisclosureEPSS 0.3%CVE-2026-82125MEDIUMSchema & Structured Data for WP & AMP 1.46 - 1.65 - Unauthenticated Non-Public Comment Content Disclosure via IDOREPSS 0.3%CVE-2024-3966MEDIUMPray For Me <= 1.0.4 - Unauthenticated Stored XSSEPSS 0.3%CVE-2026-16536MEDIUMSimple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_idEPSS 0.3%CVE-2025-15488MEDIUMResponsive Plus < 3.4.3 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.3%CVE-2023-2143—Enable SVG, WebP & ICO Upload <= 1.0.3 - Author+ Stored XSSEPSS 0.3%CVE-2026-86406HIGHUser Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership PurchaseEPSS 0.3%CVE-2026-1631MEDIUMFeeds for YouTube < 2.6.4 - Subscriber+ License Data DeletionEPSS 0.3%CVE-2026-77753MEDIUMTemporary Login Without Password < 1.9.9 - Authenticated Temporary Access Revocation Bypass via Application PasswordsEPSS 0.3%CVE-2026-76548HIGHProfile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth BypassEPSS 0.3%CVE-2026-85128HIGHChoose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Privilege Escalation via Registration Role RequestEPSS 0.3%CVE-2026-11580MEDIUMKali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOREPSS 0.3%CVE-2024-11190MEDIUMjwp-a11y <= 4.1.7 - Admin+ Stored XSSEPSS 0.3%