Jerome Bruandet

Organization: NinTechNet

18
All Time Ranking
212
All Time Discoveries
0
90 Day Published Submissions
N/A
Last Published Submission

Showing 1-20 of 212 Vulnerabilities

Title CVE ID CVSS Vector Date
Deeper Comments <= 2.1.1 - Missing Authorization to Authenticated(Subscriber+) Arbitrary Options Update 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H October 25, 2023
B2BKing <= 4.6.00 - Missing Authorization to Authenticated(Subscriber+) Information Disclosure CVE-2023-3126 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N June 3, 2023
B2BKing <= 4.6.00 - Missing Authorization to Authenticated(Subscriber+) Price Modification CVE-2023-3125 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N June 3, 2023
Elementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_option CVE-2023-3124 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H March 28, 2023
FlyingPress <= 3.9.6 - Missing Authorization CVE-2022-4948 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N November 28, 2022
Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activation CVE-2022-4950 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H April 4, 2022
AdSanity < 1.8.2 - Authenticated Arbitrary File Upload CVE-2022-4949 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H January 25, 2022
WordPress Popular Posts <= 5.3.2 - Authenticated Arbitrary File Upload CVE-2021-42362 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H November 12, 2021
uListing <= 1.6.6 - Unauthenticated SQL Injection CVE-2021-4340 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H October 28, 2021
JobSearch WP Job Board <= 1.8.1 - Missing Authorization to Settings Change CVE-2021-4352 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N October 5, 2021
JobSearch WP Job Board < = 1.8.1 - Missing Authorization on jobsearch_update_job_import_schedule_call() function CVE-2021-4364 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N October 5, 2021
JobSearch WP Job Board <= 1.8.1 - Missing Authorization to Arbitrary Options Update CVE-2021-4361 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H October 5, 2021
WP DSGVO Tools (GDPR) <= 3.1.23 - Unauthenticated Stored Cross-Site Scripting CVE-2021-4358 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N September 24, 2021
WooCommerce Multi Currency <= 2.1.17 - Missing Authorization CVE-2021-4379 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N September 13, 2021
WooCommerce Multi Currency <= 2.1.17 - Missing Authorization CVE-2021-4376 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N September 13, 2021
Multiple XforWooCommerce Add-On Plugins (Various Versions) - Missing Authorization CVE-2021-4337 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H September 7, 2021
WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update CVE-2021-4374 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H September 6, 2021
Pinterest Automatic <= 4.14.3 - Unuathenticated Arbitrary Options Update CVE-2021-4380 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H September 6, 2021
WooCommerce Dynamic Pricing and Discounts <= 2.4.1 - Stored Cross-Site Scripting CVE-2021-4372 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N August 31, 2021
WooCommerce Dynamic Pricing and Discounts <= 2.4.1 - Unauthenticated Settings Import/Export CVE-2021-4353 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N August 31, 2021

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation