Vulnerabilidades em Chimpstudio

16 resultados
Análise Vexday

Chimpstudio apresenta 16 vulnerabilidades catalogadas, com 8 classificadas como críticas (CVSS elevado), mas sem exploração ativa confirmada atualmente. A fraqueza dominante é autenticação inadequada (CWE-288), padrão que sugere controles de acesso débeis; apenas 1 CVE foi publicada nos últimos 90 dias, indicando risco relativamente estável no curto prazo.

CVE-2021-24389FoodBakery < 2.2 - Reflected Cross-Site Scripting (XSS)EPSS 3.8%CVE-2024-12035HIGHCS Framework <= 7.0 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.9%CVE-2024-13011CRITICALWP Foodbakery <= 4.7 - Unauthenticated Arbitrary File UploadEPSS 0.9%CVE-2026-15802HIGHWP Foodbakery <= 4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX ActionEPSS 0.8%CVE-2025-0316CRITICALWP Directorybox Manager <= 2.5 - Authentication BypassEPSS 0.7%CVE-2024-13182CRITICALWP Directorybox Manager <= 2.5 - Authentication BypassEPSS 0.6%CVE-2025-0181CRITICALWP Foodbakery <= 4.8 - Authentication Bypass in foodbakery_parse_requestEPSS 0.6%CVE-2025-1515CRITICALWP Real Estate Manager <= 2.8 - Authentication Bypass via Account TakeoverEPSS 0.5%CVE-2025-0180CRITICALWP Foodbakery <= 4.7 - Unauthenticated Privilege Escalation in foodbakery_registration_validationEPSS 0.5%CVE-2025-32927CRITICALWordPress FoodBakery plugin <= 3.3 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-39356CRITICALWordPress Foodbakery Sticky Cart plugin <= 3.2 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2024-12920HIGHFoodBakery | Delivery Restaurant Directory WordPress Theme <= 4.7 - Missing Authorization in Multiple FunctionsEPSS 0.4%CVE-2025-39536HIGHWordPress JobHunt Job Alerts <= 3.6 - Arbitrary Content Deletion VulnerabilityEPSS 0.4%CVE-2024-12036HIGHCS Framework <= 7.1 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.4%CVE-2024-13010MEDIUMWP Foodbakery <= 4.8 - Reflected Cross-Site ScriptingEPSS 0.3%CVE-2024-13933HIGHFoodBakery | Delivery Restaurant Directory WordPress Theme <= 4.7 - Cross-Site Request Forgery in Multiple FunctionsEPSS 0.2%