Vulnerabilidades em WPChill

59 resultados
CVE-2021-23174LOWWordPress Download Monitor plugin <= 4.4.6 - Auth. Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 83.2%CVE-2020-36708CRITICALEpsilon Framework Themes (Various Versions) - Function InjectionEPSS 65.3%CVE-2022-45354MEDIUMWordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data ExposureEPSS 38.1%CVE-2026-3584CRITICALKali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_processEPSS 7.2%CVE-2020-36721MEDIUMEpsilon Framework Themes (Various Versions) - Unauthenticated Plugin Activation/DeactivationEPSS 1.0%CVE-2025-13645HIGHModula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File DeletionEPSS 0.9%CVE-2024-12853HIGHModula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File UploadEPSS 0.8%CVE-2020-36720HIGHKali Forms <= 2.1.1 - Missing Authorization to Settings UpdateEPSS 0.8%CVE-2020-36712HIGHKali Forms <= 2.1.1 - Unauthenticated Arbitrary Post DeletionEPSS 0.7%CVE-2023-34007CRITICALWordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File UploadEPSS 0.7%CVE-2025-13646HIGHModula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race ConditionEPSS 0.7%CVE-2023-31219MEDIUMWordPress Download Monitor Plugin <= 4.8.1 is vulnerable to Server Side Request Forgery (SSRF)EPSS 0.6%CVE-2024-30501HIGHWordPress Download Monitor theme <= 4.9.4 - Auth. SQL Injection vulnerabilityEPSS 0.6%CVE-2021-36920MEDIUMWordPress plugin Download Monitor <= 4.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2024-1083MEDIUMSimple Restrict <= 1.2.6 - Missing Authorization to Sensitive Information ExposureEPSS 0.5%CVE-2023-0162MEDIUMCPO Companion <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2024-2026MEDIUMPassster <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via content_protector ShortcodeEPSS 0.5%CVE-2022-37407MEDIUMWordPress Gallery PhotoBlocks plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitiesEPSS 0.5%CVE-2024-0616MEDIUMPassster – Password Protect Pages and Content <= 4.2.6.2 - Missing Authorization to Sensitive Information ExposureEPSS 0.5%CVE-2020-36717HIGHKali Forms <= 2.1.1 - Cross-Site Request ForgeryEPSS 0.5%