Vulnerabilidades en Unknown
5591 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2026-92924MEDIUMUnlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_dataEPSS 0.2%CVE-2026-19855MEDIUMSpam protection, Honeypot, Anti-Spam by CleanTalk < 6.87 - Unauthenticated Arbitrary Shortcode Execution via Comment TextEPSS 0.2%CVE-2026-16592LOWWP Directory Kit <= 1.5.7 - Contributor+ Non-Public Listing Field Disclosure via ShortcodesEPSS 0.2%CVE-2026-92923MEDIUMUnlimited Elements For Elementor 1.5.142 - 2.0.20 - Subscriber+ SQLi via get_addon_output_dataEPSS 0.2%CVE-2026-89300MEDIUMWP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary RecipientsEPSS 0.2%CVE-2024-12750MEDIUMCompetition Form <= 2.0 - Competition Deletion via CSRFEPSS 0.2%CVE-2026-96200MEDIUMPayments for Hubtel < 1.0.2 - Unauthenticated Payment Confirmation Forgery via Delayed Payment CallbackEPSS 0.2%CVE-2026-86785MEDIUMSocial Commerce for WooCommerce <= 2.5.4 - Unauthenticated Plugin Option and Product Sync Status UpdateEPSS 0.2%CVE-2024-7687MEDIUMAZIndex <= 0.8.1 - Stored XSS via CSRFEPSS 0.2%CVE-2026-88846MEDIUMMasterStudy LMS 2.3.0 - < 3.7.50 - Unauthenticated Account Creation with Registration DisabledEPSS 0.2%CVE-2026-84169MEDIUMUPI QR Code Payment Gateway <= 1.4.3 - Unauthenticated Cross-Order Payment-Status ForgeryEPSS 0.2%CVE-2026-86837MEDIUMBookly < 28.3 - Unauthenticated Customer PII Update via Verification BypassEPSS 0.2%CVE-2026-81740MEDIUMPaytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment CallbackEPSS 0.2%CVE-2024-9233MEDIUMGS Logo Slider < 3.7.1 - Settings Update via Cross-Site Request ForgeryEPSS 0.2%CVE-2026-104118MEDIUMRazorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOREPSS 0.2%CVE-2026-84091MEDIUMSUMIT Payment Gateway for WooCommerce < 4.0.0 - Unauthenticated Payment Confirmation Forgery via bit IPNEPSS 0.2%CVE-2026-96897MEDIUMOptima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Password Rotation via ihf_clear_cacheEPSS 0.2%CVE-2025-15691MEDIUMWPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in FormsEPSS 0.2%CVE-2025-15520MEDIUMRegistrationMagic <= 6.0.7.2 - Subscriber+ Sensitive Data DisclosureEPSS 0.2%CVE-2025-6572MEDIUMOpenStreetMap for Gutenberg and WPBakery Page Builder <= 1.2.0 - Contributor+ Stored XSSEPSS 0.2%