Vulnerabilidades en Unknown
5582 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2025-11237MEDIUMMake Email Customizer for WooCommerce <= 1.0.6 - Subscriber+ Arbitrary Options UpdateEPSS 0.3%CVE-2022-4745MEDIUMWP Customer Area < 8.1.4 - Unauthorised Actions via CSRFEPSS 0.3%CVE-2026-85573HIGHAll in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG UploadEPSS 0.3%CVE-2026-14190MEDIUMSina Extension for Elementor < 3.10.2 - Reflected XSSEPSS 0.3%CVE-2026-16992MEDIUMCreate by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and PublicationEPSS 0.3%CVE-2026-14561MEDIUMAuthora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP DisclosureEPSS 0.3%CVE-2026-10525MEDIUMNEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form SubmissionEPSS 0.3%CVE-2025-15491MEDIUMPost Slides <= 1.0.1 - Contributor+ Local File InclusionEPSS 0.3%CVE-2026-10824MEDIUMMasteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and DeletionEPSS 0.3%CVE-2026-12688MEDIUMProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN ForgeryEPSS 0.3%CVE-2026-77695MEDIUMWoo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Disclosure and ManipulationEPSS 0.3%CVE-2026-15931MEDIUMSimple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber NameEPSS 0.3%CVE-2026-11588MEDIUMEONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post CreationEPSS 0.3%CVE-2023-3209—MStore API < 3.9.7 - Settings Update via CSRFEPSS 0.3%CVE-2026-2811MEDIUMAjaxify Comments < 3.2 - Unauthenticated HTTP Header InjectionEPSS 0.3%CVE-2026-14845MEDIUMNewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post WidgetEPSS 0.3%CVE-2026-17019MEDIUMJetEngine < 3.8.13.1 - Unauthenticated Stored XSS via Form File Upload (SVG)EPSS 0.3%CVE-2026-85009MEDIUMRestroPress <= 3.4.6 - Unauthenticated Order Enumeration and Order Note Modification via Payment RecoveryEPSS 0.3%CVE-2026-4432MEDIUMYITH WooCommerce Wishlist < 4.13.0 - Unauthenticated Arbitrary Wishlist Renaming via IDOREPSS 0.3%CVE-2025-1033MEDIUMBadgearoo <= 1.0.14 - Admin+ Stored XSSEPSS 0.3%