Krzysztof Zając

Organization: CERT PL

7
All Time Ranking
461
All Time Discoveries
37
90 Day Published Submissions
1 Apr '25
Last Published Submission

About

Finding WordPress vulnerabilities using https://kazet.cc/2022/02/03/fuzzing-wordpress-plugins.html

Submitted 200 Vulnerabilities
Submitted 200 Vulnerabilities
February 19, 2025
Submitted XSS Vulnerability
Submitted XSS Vulnerability
September 4, 2024
Submitted 100 Vulnerabilities
Submitted 100 Vulnerabilities
April 22, 2024
Submitted 75 Vulnerabilities
Submitted 75 Vulnerabilities
April 4, 2024
Submitted 50 Vulnerabilities
Submitted 50 Vulnerabilities
March 19, 2024
Submitted 25 Vulnerabilities
Submitted 25 Vulnerabilities
February 27, 2024
Submitted 10 Vulnerabilities
Submitted 10 Vulnerabilities
February 9, 2024
Submitted 5 Vulnerabilities
Submitted 5 Vulnerabilities
January 23, 2024
1337 Vulnerability Researcher
1337 Vulnerability Researcher
January 2, 2024
Submitted 1 Vulnerability
Submitted 1 Vulnerability
January 2, 2024

Showing 21-40 of 461 Vulnerabilities

Title CVE ID CVSS Vector Date
Custom Post Type Date Archives <= 2.7.1 - Missing Authorization to Unauthenticated Arbitrary Shortcode Execution CVE-2025-1510 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L February 21, 2025
Show Me The Cookies <= 1.0 - Unauthenticated Arbitrary Shortcode Execution CVE-2025-1509 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L February 21, 2025
WP-Appbox <= 4.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via appbox Shortcode CVE-2025-1489 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N February 20, 2025
Events Calendar Made Simple – Pie Calendar <= 1.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via piecal Shortcode CVE-2025-1410 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N February 20, 2025
Newpost Catch <= 1.3.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via npc Shortcode CVE-2025-1406 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N February 20, 2025
AMO Team Showcase <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via amoteam_skills Shortcode CVE-2025-1407 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N February 20, 2025
WPMobile.App <= 11.56 - Open Redirect via 'redirect' Parameter CVE-2024-13888 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N February 19, 2025
Trash Duplicate and 301 Redirect <= 1.9 - Missing Authorization to Unauthenticated Arbitrary Post Deletion CVE-2024-13468 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N February 18, 2025
Booking Package <= 1.6.72 - Reflected Cross-Site Scripting via Locale Parameter CVE-2024-13508 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N February 18, 2025
Wonder Video Embed <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVE-2024-13743 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N February 18, 2025
Super Testimonials <= 4.0.1 - Unauthenticated Stored Cross-Site Scripting CVE-2024-13704 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N February 17, 2025
WP Project Manager <= 2.6.17 - Authenticated (Subscriber+) SQL Injection via orderby Parameter CVE-2024-13500 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N February 14, 2025
WP Project Manager <= 2.6.17 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update CVE-2024-13752 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H February 14, 2025
Oliver POS – A WooCommerce Point of Sale (POS) <= 2.4.2.3 - Sensitive Information Exposure to Privilege Escalation CVE-2024-13513 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H February 14, 2025
iControlWP – Multiple WordPress Site Manager <= 4.4.5 - Unauthenticated PHP Object Injection CVE-2024-13742 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H January 30, 2025
CP Contact Form with PayPal <= 1.3.52 - Cross-Site Request Forgery CVE-2024-13758 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N January 29, 2025
WP Hotel Booking <= 2.1.6 - Missing Authorization to Authenticated (Subscriber+) User Email Retrieval CVE-2024-13447 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N January 21, 2025
WP Job Manager – Company Profiles <= 1.7 - Reflected Cross-Site Scripting CVE-2023-6978 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N December 3, 2024
Shoutcast Icecast HTML5 Radio Player <= 2.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE-2024-8666 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N October 24, 2024
KB Support – WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions CVE-2024-8548 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N September 30, 2024

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation