Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP User Profile Avatar | 0 ~ 1.0.1 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-1746 | Testimonial Slider < 2.3.8 - Admin+ Stored XSS | |
| CVE-2024-2858 | Simple Buttons Creator <= 1.04 - Aribtrary Button Deletion via CSRF | |
| CVE-2024-2857 | Simple Buttons Creator <= 1.04 - Unauthenticated Stored XSS | |
| CVE-2024-2836 | Super Socializer < 7.13.64 - Editor+ Stored XSS | |
| CVE-2024-2739 | Advance Search <= 1.1.6 - Shortcode Deletion via CSRF | |
| CVE-2024-1849 | WP Customer Reviews < 3.7.1 - Malicious Redirect via HTTP-EQUIV Injection | |
| CVE-2024-1846 | Responsive Tabs < 4.0.7 - Contributor+ Stored XSS | |
| CVE-2024-1755 | NPS computy <= 2.7.5 - Results Deletion via CSRF | |
| CVE-2024-1754 | NPS computy <= 2.7.5 - Admin+ Stored XSS | |
| CVE-2023-7201 | Everest Backup < 2.2.5 - Admin+ Arbitrary File Upload | |
| CVE-2024-1712 | Carousel Slider < 2.2.7 - Editor+ Stored XSS | |
| CVE-2024-1660 | Top Bar < 3.0.5 - Admin+ Stored XSS | |
| CVE-2024-1310 | WooCommerce < 8.6 - Contributor+ Private/Draft Products Access | |
| CVE-2024-1307 | Smart Forms < 2.6.94 - Subscriber+ Edit Entries via Broken Access Control | |
| CVE-2024-1306 | Smart Forms < 2.6.94 - Edit Entries via CSRF | |
| CVE-2024-1204 | Meta Box < 5.9.4 - Contributor+ Arbitrary Posts' Custom Field Disclosure | |
| CVE-2024-0902 | Fancy Product Designer < 6.1.81 - Admin+ Cross Site Scripting via Product Title | |
| CVE-2024-0399 | WooCommerce Customers Manager < 29.7 - Subscriber+ SQL Injection |
No comments yet