Vulnerabilidades em redefiningtheweb
9 resultadosAnálise Vexday
O fornecedor redefiningtheweb possui 2 CVEs catalogadas, com 1 divulgação nos últimos 90 dias, indicando risco recente. Nenhuma vulnerabilidade está sob ataque ativo documentado (KEV) e não há críticas de severidade máxima, o que reduz a urgência operacional. A fraqueza predominante (CWE-22 - Path Traversal) apresenta potencial de contorno de controles de acesso, requerendo atenção no contexto da arquitetura de deployments específicos.
CVE-2024-9935HIGHPDF Generator Addon for Elementor Page Builder <= 2.0.0 - Unauthenticated Arbitrary File DownloadEPSS 7.4%CVE-2024-9289CRITICALWordPress & WooCommerce Affiliate Program <= 8.4.1 - Authentication Bypass to Account Takeover and Privilege EscalationEPSS 0.6%CVE-2025-24569HIGHWordPress PDF Generator Addon for Elementor Page Builder plugin <= 1.7.5 - Arbitrary File Read vulnerabilityEPSS 0.5%CVE-2025-39518HIGHWordPress BMA Lite plugin <= 1.4.2 - SQL Injection vulnerabilityEPSS 0.5%CVE-2026-7559MEDIUMAffilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Status ModificationEPSS 0.3%CVE-2025-64231CRITICALWordPress WordPress Contact Form 7 PDF, Google Sheet & Database plugin <= 3.0.0 - Arbitrary File Upload vulnerabilityEPSS 0.3%CVE-2024-50449MEDIUMWordPress PDF Generator Addon for Elementor Page Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-31850MEDIUMWordPress PDF Generator Addon for Elementor Page Builder plugin <= 2.1.0 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-48342MEDIUMWordPress Dynamic Pricing & Discounts Lite for WooCommerce plugin <= 2.0.3 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.1%