mikemyers

63
All Time Ranking
71
All Time Discoveries
45
90 Day Published Submissions
10 Apr '25
Last Published Submission
Submitted 50 Vulnerabilities
Submitted 50 Vulnerabilities
March 19, 2025
Submitted 25 Vulnerabilities
Submitted 25 Vulnerabilities
January 21, 2025
Submitted 10 Vulnerabilities
Submitted 10 Vulnerabilities
December 5, 2024
1337 Vulnerability Researcher
1337 Vulnerability Researcher
November 26, 2024
Submitted 5 Vulnerabilities
Submitted 5 Vulnerabilities
November 22, 2024
Submitted XSS Vulnerability
Submitted XSS Vulnerability
November 14, 2024
Submitted 1 Vulnerability
Submitted 1 Vulnerability
November 8, 2024

Showing 1-20 of 71 Vulnerabilities

Title CVE ID CVSS Vector Date
Cost Calculator Builder <= 3.2.67 - Authenticated (Subscriber+) SQL Injection via order_ids Parameter CVE-2025-2128 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N April 10, 2025
Everest Forms <= 3.1.1 - Reflected Cross-Site Scripting CVE-2025-3421 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 10, 2025
Everest Forms <= 3.1.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution CVE-2025-3422 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N April 10, 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation CVE-2025-3102 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H April 9, 2025
Motors – Car Dealership & Classified Listings Plugin <= 1.4.64 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation CVE-2025-2807 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H April 7, 2025
Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.8.9.1 - Unauthenticated Limited Local File Inclusion CVE-2025-2270 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H April 3, 2025
TagDiv Composer <= 5.3 - Unauthenticated Arbitrary PHP Object Instantiation CVE-2024-13645 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H April 3, 2025
Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation CVE-2025-2075 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H April 3, 2025
LuckyWP Table of Contents <= 2.1.10 - Cross-Site Request Forgery to Reflected Cross-Site Scripting CVE-2025-2299 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N April 2, 2025
Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Upload CVE-2025-2008 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H March 31, 2025
Shortcodes by United Themes <= 5.1.6 - Unauthenticated Arbitrary Shortcode Execution CVE-2024-13557 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N March 28, 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion CVE-2025-2294 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H March 27, 2025
WP Compress <= 6.30.15 - Authenticated (Subscriber+) Missing Authorization via Multiple Functions CVE-2025-2110 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H March 25, 2025
Ultimate Dashboard <= 3.8.7 - Missing Authorization to Authenticated (Subscriber+) Plugin Modules Activation/Deactivation CVE-2025-2276 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N March 25, 2025
Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Deletion CVE-2025-2007 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H March 25, 2025
WP Compress <= 6.30.15 - Unauthenticated Server-Side Request Forgery via init Function CVE-2025-2109 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N March 24, 2025
Directorist <= 8.2 - Missing Authorization to Unauthenticated Arbitrary Post Publishing CVE-2025-2224 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N March 24, 2025
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.1 - Unauthenticated SQL Injection via 'automationId' CVE-2025-2186 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N March 21, 2025
Age Gate <= 3.5.3 - Unauthenticated Local PHP File Inclusion via 'lang' CVE-2025-2505 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H March 19, 2025
LifterLMS <= 8.0.1 - Missing Authorization to Unauthenticated Post Trashing CVE-2025-2290 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N March 18, 2025

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation