Vulnerabilidades em Ays Pro

56 resultados
Análise Vexday

Com 54 CVEs catalogadas e nenhuma em exploração ativa no catálogo CISA KEV, o perfil de risco do Ays Pro situa-se abaixo da média geral do catálogo, sem registros de falhas críticas ou provas de conceito públicas conhecidas. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode viabilizar sequestro de sessão e ataques de engenharia social quando não mitigado adequadamente. A CVE mais relevante no momento, CVE-2021-24483, apresenta pontuação EPSS de 0,0141, indicando probabilidade de exploração relativamente baixa no curto prazo. A presença de uma CVE surgida nos últimos 90 dias sugere que a superfície de ataque ainda está em evolução, recomendando monitoramento contínuo mesmo diante do cenário atual menos crítico.

CVE-2021-24483Poll Maker < 3.2.1 - Authenticated Blind SQL InjectionsEPSS 1.4%CVE-2021-24457Portfolio Responsive Gallery < 1.1.8 - Authenticated Blind SQL InjectionsEPSS 1.4%CVE-2021-24461FAQ Builder < 1.3.6 - Authenticated Blind SQL InjectionsEPSS 1.4%CVE-2021-24459Survey Maker < 1.5.6 - Authenticated Blind SQL InjectionsEPSS 1.4%CVE-2021-24462Photo Gallery by Ays - Responsive Image Gallery < 4.4.4 - Authenticated Blind SQL InjectionsEPSS 1.4%CVE-2021-24458Popup box < 2.3.4 - Authenticated Blind SQL InjectionsEPSS 1.4%CVE-2021-24463Image Slider by Ays - Responsive Slider and Carousel < 2.5.0 - Authenticated Blind SQL InjectionEPSS 1.4%CVE-2021-24460Popup Like box - Page Plugin < 3.5.3 - Authenticated Blind SQL InjectionsEPSS 1.4%CVE-2021-24484Secure Copy Content Protection and Content Locking < 2.6.7 - Authenticated Blind SQL InjectionsEPSS 1.3%CVE-2021-24456Quiz Maker < 6.2.0.9 - Multiple Authenticated Blind SQL InjectionsEPSS 1.3%CVE-2025-62039HIGHWordPress AI ChatBot with ChatGPT and Content Generator by AYS plugin <= 2.6.6 - Sensitive Data Exposure vulnerabilityEPSS 1.3%CVE-2023-50904MEDIUMWordPress Poll Maker plugin <= 4.8.0 - Broken Access Control vulnerabilityEPSS 0.7%CVE-2025-26971HIGHWordPress Poll Maker <= 5.6.5 - SQL Injection vulnerabilityEPSS 0.5%CVE-2024-56295MEDIUMWordPress Poll Maker plugin <= 5.5.6 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-24577MEDIUMWordPress Poll Maker plugin <= 5.5.0 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-32133MEDIUMWordPress Secure Copy Content Protection and Content Locking plugin <= 4.5.5 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2025-30905HIGHWordPress Secure Copy Content Protection and Content Locking plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2025-30774HIGHWordPress Quiz Maker plugin <= 6.6.8.7 - SQL Injection vulnerabilityEPSS 0.4%CVE-2023-45766MEDIUMWordPress Poll Maker plugin <= 4.7.1 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-57631HIGHWordPress Popup box plugin <= 6.0.1 - SQL Injection vulnerabilityEPSS 0.3%