Vulnerabilities in saadiqbal

49 results
Vexday analysis

Saadiqbal apresenta 46 vulnerabilidades catalogadas, com apenas 2 classificadas como críticas e nenhuma sob exploração ativa confirmada. A fraqueza dominante é CWE-862 (Autorização Ausente), indicando falhas no controle de acesso, enquanto o ritmo de descoberta permanece moderado com 5 vulnerabilidades nos últimos 90 dias.

CVE-2024-1639MEDIUMLicense Manager for WooCommerce <= 3.0.6 - Improper Authorization to Authenticated(Contributor+) Sensitive Information ExposureEPSS 0.4%CVE-2024-13844MEDIUMPost SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns ParameterEPSS 0.4%CVE-2026-12144HIGHWholesale for WooCommerce <= 2.0.5 - Authenticated (Author+) Privilege Escalation via 'user_role_set' ParameterEPSS 0.4%CVE-2024-8725MEDIUMAdvanced File Manager <= 5.2.8 - Authenticated (Subscriber+) Limited File UploadEPSS 0.4%CVE-2025-3453MEDIUMPassword Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products <= 2.7.7 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2024-0656MEDIUMPassword Protected <= 2.6.6 - Authenticated (Admin+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2024-0437MEDIUMPassword Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease <= 2.6.6 - Missing Authorization to Sensitive Information ExposureEPSS 0.3%CVE-2024-8658MEDIUMmyCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 - Missing Authorization to Unauthenticated Database UpgradeEPSS 0.3%CVE-2026-0832HIGHNew User Approve <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information DisclosureEPSS 0.3%CVE-2026-11995MEDIUMGutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification/Trash via process_bulk_action()EPSS 0.3%CVE-2024-10187MEDIUMmyCred <= 2.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_link ShortcodeEPSS 0.3%CVE-2025-0521HIGHPost SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-12770MEDIUMNew User Approve <= 3.0.9 - Unauthenticated Sensitive Information Disclosure via Type JugglingEPSS 0.3%CVE-2025-11244LOWPassword Protected <= 2.7.11 - Unauthenticated Authorization Bypass via IP Address SpoofingEPSS 0.3%CVE-2025-12887MEDIUMPost SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token UpdateEPSS 0.3%CVE-2024-13362MEDIUMFreemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url ParameterEPSS 0.3%CVE-2025-12362MEDIUMmyCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7 - Missing Authorization to Unauthenticated Withdrawal Request ApprovalEPSS 0.3%CVE-2024-13805MEDIUMAdvanced File Manager <= 5.2.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File UploadEPSS 0.3%CVE-2026-8607MEDIUMmyCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrap' Shortcode AttributeEPSS 0.3%CVE-2026-12097MEDIUMUser Management <= 1.2 - Missing Authorization to Unauthenticated Plugin Settings ModificationEPSS 0.3%