Rafie Muhammad

Organization: Patchstack

2
All Time Ranking
559
All Time Discoveries
0
90 Day Published Submissions
N/A
Last Published Submission

Showing 441-460 of 559 Vulnerabilities

Title CVE ID CVSS Vector Date
JetElements For Elementor <= 2.6.13 - Missing Authorization to Unauthenticated Arbitrary Attachment Download CVE-2023-48759 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N November 28, 2023
Porto Theme - Functionality <= 2.11.1 - Missing Authorization CVE-2023-48739 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N November 23, 2023
Pre-Publish Checklist <= 1.1.1 - Insecure Direct Object Reference to Arbitrary Post '_ppc_meta_key' Update CVE-2023-44151 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N September 22, 2023
Multiple ServMask Plugins <= (Various Versions) - Missing Authorization to Access Token Update CVE-2023-40004 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N August 30, 2023
Paid Memberships Pro CCBill Gateway <= 0.3 - Insufficient Authorization CVE-2023-40608 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N August 17, 2023
Ninja Forms <= 3.6.25 - Missing Authorization to Contributor+ Form Submission Export CVE-2023-38386 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N July 25, 2023
Premium Addons PRO <= 2.9.0 - Sensitive Information Exposure CVE-2023-37868 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N July 10, 2023
WooCommerce Box Office <= 1.1.51 - Missing Authorization CVE-2023-34003 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N June 2, 2023
Yoast SEO Premium <= 20.4 - Missing Authorization to Zapier Key Reset CVE-2023-28775 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N May 9, 2023
Jetpack < 12.7 - Authenticated(Contributor+) Clickjacking via Iframe Injection CVE-2023-47774 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N November 16, 2023
ShortPixel Image Optimizer <= 5.6.3 - Authenticated (Editor+) SQL Injection CVE-2024-48043 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N October 13, 2024
GiveWP <= 2.20.2 - Authenticated Arbitrary File Read CVE-2022-31475 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N July 12, 2022
WooCommerce Ship to Multiple Addresses <= 3.8.5 - Reflected Cross-Site Scripting CVE-2023-37873 4.4 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N July 10, 2023
Otter - Gutenberg Block <= 3.0.3 - Missing Authorization CVE-2024-51671 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N November 1, 2024
SEOPress <= 8.1.1 - Missing Authorization CVE-2024-50456 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N October 24, 2024
SEOPress <= 8.1.1 - Missing Authorization CVE-2024-50455 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N October 24, 2024
Custom Twitter Feeds (Tweets Widget) <= 2.2.3 - Cross-Site Request Forgery CVE-2024-49685 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N October 21, 2024
WP Content Copy Protection & No Right Click <= 3.5.9 - Cross-Site Request Forgery CVE-2024-49306 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N October 15, 2024
Simple Custom Post Order <= 2.5.7 - Missing Authorization CVE-2024-49321 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N October 15, 2024
Table of Contents Plus <= 2411 - Cross-Site Request Forgery CVE-2024-49250 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N October 14, 2024

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation