Vulnerabilidades en cozmoslabs
62 resultadosAnálisis Vexday
Cozmoslabs acumula 19 vulnerabilidades catalogadas, com 3 classificadas como críticas, predominantemente relacionadas a Cross-Site Scripting (CWE-79). Nenhuma vulnerabilidade está sob exploração ativa no momento e o fornecedor não registrou publicações recentes nos últimos 90 dias, indicando risco estável e sem pressão imediata de remediação.
CVE-2026-19632CRITICALTranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link DisclosureEPSS 9.0%CVE-2026-15826CRITICALUser Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' ParameterEPSS 3.9%CVE-2022-0653MEDIUMProfile Builder – User Profile & User Registration Forms <= 3.6.1 Reflected Cross-Site ScriptingEPSS 2.7%CVE-2024-0324HIGHUser Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_updateEPSS 2.4%CVE-2023-2297CRITICALProfile Builder – User Profile & User Registration Forms <= 3.9.0 - Insecure Password Reset MechanismEPSS 1.0%CVE-2026-17505MEDIUMTranslatePress <= 3.2.5 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2025-30773HIGHWordPress TranslatePress plugin <= 2.9.6 - PHP Object Injection VulnerabilityEPSS 0.8%CVE-2023-0814MEDIUMProfile Builder – User Profile & User Registration Forms <= 3.9.0 - Sensitive Information Disclosure via ShortcodeEPSS 0.8%CVE-2026-7647HIGHProfile Builder Pro <= 3.14.5 - Unauthenticated PHP Object InjectionEPSS 0.6%CVE-2025-8895CRITICALWP Webhooks <= 3.3.5 - Unauthenticated Arbitrary File CopyEPSS 0.6%CVE-2025-54017HIGHWordPress Paid Member Subscriptions <= 2.15.4 - Local File Inclusion VulnerabilityEPSS 0.6%CVE-2024-12919CRITICALPaid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.7 - Authentication Bypass via pms_payment_idEPSS 0.6%CVE-2024-1390MEDIUMPaid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.11.1 - Missing Authorization via creating_pricing_table_pageEPSS 0.5%CVE-2026-89412HIGHTranslatePress <= 3.3.5 - Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion PanelEPSS 0.5%CVE-2026-76053HIGHTranslatePress <= 3.3.3 - Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML ParserEPSS 0.5%CVE-2024-1389MEDIUMPaid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.11.1 - Missing Authorization via pms_stripe_connect_handle_authorization_returnEPSS 0.5%CVE-2026-82607MEDIUMCozmoslabs Profile Builder Plugin Avatar Simple Upload AJAX admin-ajax.php wppb_ajax_simple_avatar unrestricted uploadEPSS 0.5%CVE-2024-22141MEDIUMWordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2026-78267CRITICALWordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2024-11291MEDIUMPaid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.4 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.5%