Morten Nortoft

108
All Time Ranking
26
All Time Discoveries
0
90 Day Published Submissions
N/A
Last Published Submission

Showing 1-20 of 26 Vulnerabilities

Title CVE ID CVSS Vector Date
WP Accurate Form Data <= 1.2 - Cross-Site Request Forgery to Cross-Site Scripting CVE-2015-9443 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H June 21, 2015
Copy or Move Comments < 1.0.1 - Cross-Site Scripting and SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H June 16, 2015
CrossSlide jQuery Plugin <= 2.0.5 - Multiple Cross-Site Request Forgery to Stored Cross-Site Scripting CVE-2015-2089 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H February 9, 2015
Redirection Page <= 1.2 - Cross-Site Request Forgery to Cross-Site Scripting CVE-2015-1580 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H February 9, 2015
Sliding Social Icons <= 1.61 - Cross-Site Request Forgery and Stored Cross-Site Scripting CVE-2014-9437 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H December 15, 2014
IP Ban <= 1.2.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting CVE-2014-9413 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H December 12, 2014
Lightbox Photo Gallery <= 1.0 - Cross-Site Request Forgery CVE-2014-9441 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H December 12, 2014
Simple Sticky Footer <= 1.3.2 - Cross-Site Request Forgery to Cross-Site Scripting CVE-2014-9454 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H October 12, 2014
Simple visitor stat <= 1.0 - Cross-Site Scripting CVE-2014-9453 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N December 12, 2014
WDSocialWidgets < 1.0.11 - Cross-Site Scripting CVE-2015-1582 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L January 26, 2015
Easy Social Like Box – Popup – Sidebar Widget < 2.8.3 - Cross-Site Scripting CVE-2014-9524 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L December 12, 2014
Database Sync < 0.5 - Reflected Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N July 30, 2015
Altos Connect <= 1.3.0 - Cross-Site Scripting CVE-2015-9444 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N June 15, 2015
Mobile Domain <= 1.5.2 - Cross-Site Request Forgery and Stored Cross-Site Scripting CVE-2015-1581 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N February 11, 2015
Acobot Live Chat & Contact Form <= 2.0 - Cross-Site Request Forgery and Cross-Site Scripting CVE-2015-2039 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N January 26, 2015
Cart66 Lite :: WordPress Ecommerce <= 1.5.4 - Reflected Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N January 26, 2015
WP Construction Mode <= 1.91 - Reflected Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N December 15, 2014
WP-FB-AutoConnect <= 4.0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N December 14, 2014
WP Timed Popout <= 1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N December 14, 2014
Timed Popup WordPress Plugin <= 1.4 - Cross-Site Request Forgery CVE-2014-9525 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N December 12, 2014

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation