Erwan LR

Organization: WPScan

34
All Time Ranking
125
All Time Discoveries
0
90 Day Published Submissions
N/A
Last Published Submission

Showing 61-80 of 125 Vulnerabilities

Title CVE ID CVSS Vector Date
Conditional Menus <= 1.2.0 - Reflected Cross-Site Scripting CVE-2023-2654 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 24, 2023
Multiple Wow-Company Plugins (Various Versions) -- Reflected Cross-Site Scripting via 'page' parameter CVE-2023-2362 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 22, 2023
Easy Forms for Mailchimp <= 6.8.8 - Reflected Cross-Site Scripting CVE-2023-2518 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 22, 2023
Icegram Engage <= 3.1.11 - Reflected Cross-Site Scripting CVE-2023-2398 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 22, 2023
Photo Gallery by Ays <= 5.1.6 - Reflected Cross-Site Scripting CVE-2023-2568 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 16, 2023
Quiz Maker <= 6.4.2.6 - Reflected Cross-Site Scripting CVE-2023-2571 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 15, 2023
ConvertKit <= 2.2.0 - Reflected Cross-Site Scripting CVE-2023-2337 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 15, 2023
Stop Spammers Security <= 2022.6 - Authenticated (Admin+) Stored Cross-Site Scripting CVE-2023-2489 4.4 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N May 15, 2023
Stop Spammers Security <= 2022.6 - Reflected Cross-Site Scripting CVE-2023-2488 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 15, 2023
Survey Maker <= 3.4.6 - Reflected Cross-Site Scripting via 'page' parameter CVE-2023-2572 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 15, 2023
10Web Social Post Feed <= 1.2.8 - Reflected Cross-Site Scripting CVE-2023-2503 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 10, 2023
Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue <= 3.1.60 - Reflected Cross-Site Scripting via 'lang' CVE-2023-2472 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 10, 2023
WP Fastest Cache <= 1.1.4 - Authenticated(Administrator+) Blind Server Side Request Forgery via check_url CVE-2023-1938 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H May 2, 2023
Loginizer <= 1.7.8 - Reflected Cross-Site Scripting via 'limit_session[count]' CVE-2023-2296 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 2, 2023
Tiempo.com <= 0.1.2 - Reflected Cross-Site Scripting CVE-2023-2272 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 25, 2023
Tiempo.com <= 0.1.2 - Cross-Site Request Forgery to Shortcode Deletion CVE-2023-2271 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N April 25, 2023
YARPP - Yet Another Related Posts Plugin <= 5.30.2 - Authenticated (Subscriber+) SQL Injection via Shortcode CVE-2023-0579 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H April 25, 2023
Ninja Forms Contact Form <= 3.6.21 - Reflected Cross-Site Scripting via 'title' CVE-2023-1835 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 24, 2023
ChatBot <= 4.4.4 - Unauthenticated Stored Cross-Site Scripting via Cross-Site Request Forgery CVE-2023-1011 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 20, 2023
Helpie FAQ <= 1.9.8 - Reflected Cross-Site Scripting CVE-2023-1891 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 18, 2023

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation