Vulnerabilidades em properfraction
34 resultadosAnálise Vexday
A properfraction possui 30 vulnerabilidades registradas, com apenas 1 crítica e nenhuma sob exploração ativa conhecida, reduzindo o risco imediato. A fraqueza dominante é Cross-Site Scripting (CWE-79), padrão em aplicações web, com 4 novas publicações nos últimos 90 dias indicando manutenção contínua de descobertas. O risco permanece contido pela ausência de exploração ativa, mas requer atenção regular a atualizações.
CVE-2024-11083MEDIUMProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.4%CVE-2026-3309MEDIUMPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Checkout Billing FieldsEPSS 0.4%CVE-2024-2867MEDIUMPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2024-1046MEDIUMPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2026-4949MEDIUMProfilePress <= 4.16.12 - Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan SubscriptionEPSS 0.4%CVE-2024-12309MEDIUMRate My Post – Star Rating Plugin by FeedbackWP <= 4.2.4 - Unauthenticated Voting On Scheduled PostsEPSS 0.3%CVE-2026-3445HIGHPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment BypassEPSS 0.3%CVE-2024-2861MEDIUMProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel WidgetEPSS 0.3%CVE-2024-8628MEDIUMPopup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin <= 1.2.70.3 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2024-0428HIGHIndex Now <= 2.6.3 - Cross-Site Request Forgery via reset_formEPSS 0.3%CVE-2025-58596MEDIUMWordPress MailOptin Plugin <= 1.2.75.0 - Cross Site Scripting (XSS) VulnerabilityEPSS 0.2%CVE-2026-41556MEDIUMWordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-66703MEDIUMWordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-59520MEDIUMWordPress CrawlWP SEO plugin <= 3.0.16 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.1%