John Castro

199
All Time Ranking
13
All Time Discoveries
0
90 Day Published Submissions
N/A
Last Published Submission

13 Vulnerabilities

Title CVE ID CVSS Vector Date
TI WooCommerce Wishlist <= 2.9.0 - Unauthenticated SQL Injection via 'lang' CVE-2024-9156 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N September 19, 2024
YITH WooCommerce Ajax Search <= 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE-2024-7846 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N September 2, 2024
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.11.8 - Authentication Bypass CVE-2024-6695 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H July 10, 2024
Andrea Pernici News Sitemap for Google <= 1.0.16 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE-2021-36912 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N May 4, 2022
Image Hover Effects Ultimate <= 9.6.1 - Unauthenticated Arbitrary Options Update CVE-2021-36888 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H December 15, 2021
Comment Engine Pro <= 1.0 - Authenticated (Editor+) Stored Cross-Site Scripting CVE-2021-36911 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N October 7, 2021
Woocommerce Customers Manager <= 26.4 - Authenticated Account Creation and Privilege Escalation 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H February 24, 2021
NextScripts: Social Networks Auto-Poster <= 4.3.17 - Missing Authorization CVE-2020-36831 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N September 5, 2020
YITH WooCommerce Ajax Product Filter <= 3.11.0 - Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N June 22, 2020
Icegram <= 1.10.28.2 - Cross-Site Scripting CVE-2019-15830 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N July 9, 2019
WP Live Chat Support <= 8.0.27 - Unauthenticated Stored Cross-Site Scripting CVE-2019-14950 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N May 15, 2019
Advanced Contact form 7 DB <= 1.6.0 - SQL Injection 8.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N April 11, 2019
YITH WooCommerce Wishlist <= 2.1.2 - SQL Injection 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N January 16, 2018

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation