Rafie Muhammad

Organization: Patchstack

2
All Time Ranking
559
All Time Discoveries
0
90 Day Published Submissions
N/A
Last Published Submission

Showing 161-180 of 559 Vulnerabilities

Title CVE ID CVSS Vector Date
Thrive Theme Builder < 3.24.0 - Missing Authorization CVE-2023-47783 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L November 14, 2023
JupiterX Core 3.0.0 - 3.3.0 - Missing Authorization CVE-2023-38385 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L August 13, 2023
Indeed Membership Pro <= 12.7 - Unauthenticated PHP Object Injection CVE-2024-43242 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H August 12, 2024
Uncode Core <= 2.8.8 - Authenticated (Subscriber+) Arbitrary File Deletion CVE-2023-51500 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H December 21, 2023
Bookly <= 21.7.1 - Arbitrary File Deletion CVE-2023-26526 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H May 11, 2023
JupiterX Theme <= 3.0.0 - Authenticated Local File Inclusion via print_pane CVE-2023-32110 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N May 3, 2023
WPForms User Registration <= 2.1.0 - Missing Authorization to Authenticated (Contributor+) Privilege Escalation CVE-2023-52209 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H July 18, 2024
LiteSpeed Cache <= 6.4.1 - Unauthenticated Sensitive Information Exposure via Log Files CVE-2024-44000 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N September 5, 2024
Brooklyn <= 4.9.7.6 - PHP Object Injection CVE-2024-24926 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H February 9, 2024
WebinarIgnition <= 3.05.0 - Authenticated(Subscriber+) PHP Object Injection CVE-2023-51422 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H December 27, 2023
Avada <= 7.11.1 - Authenticated(Contributor+) Arbitrary File Upload via 'ajax_import_options' CVE-2023-39307 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H August 10, 2023
WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure CVE-2023-34000 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N June 13, 2023
User Registration <= 2.3.2.1 - PHP Object Injection CVE-2023-27459 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H March 21, 2023
NitroPack <= 1.16.7 - Unauthenticated Arbitrary Shortcode Execution CVE-2024-43922 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L August 26, 2024
Local Delivery Drivers for WooCommerce <= 1.9.0 - Missing Authorization to Driver Account Takeover CVE-2023-51481 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L December 27, 2023
Multiple Plugins by Crocoblock <= (Various Versions) - Missing Authorization to Unauthenticated Unauthorized Action CVE-2023-48760 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L November 28, 2023
Simple Membership <= 4.3.4 - Privilege escalation via Registration CVE-2023-41957 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L September 25, 2023
LearnPress <= 4.2.3 - Missing Authorization to Information Exposure CVE-2023-36515 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L July 4, 2023
Essential Addons for Elementor Pro <= 5.4.8 - Unauthenticated Server-Side Request Forgery CVE-2023-32245 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L May 15, 2023
HUSKY <= 1.3.6.1 - Authenticated (Shop Manager+) Arbitrary Options Update CVE-2024-43121 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H August 7, 2024

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation