Vulnerabilities in scottpaterson

12 results
Vexday analysis

Scott Patterson apresenta um perfil de risco baixo com 12 vulnerabilidades catalogadas, nenhuma delas atualmente sob ataque ativo (KEV) ou com severidade crítica. A fraqueza dominante é CWE-79 (cross-site scripting), com apenas 1 nova vulnerabilidade publicada nos últimos 90 dias, indicando risco estável e sem pressão imediata de remediação.

CVE-2024-9593HIGHTime Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code ExecutionEPSS 12.3%CVE-2024-10683MEDIUMContact Form 7 - PayPal & Stripe Add-on <= 2.3.1 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2024-12423MEDIUMContact Form 7 Redirect & Thank You Page <= 1.0.7 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2024-13728MEDIUMAccept Donations with PayPal & Stripe <= 1.4.4 - Reflected Cross-Site ScriptingEPSS 0.3%CVE-2024-1719MEDIUMEasy PayPal & Stripe Buy Now Button <= 1.8.3 & Contact Form 7 – PayPal & Stripe Add-on <= 2.1 - Cross-Site Request Forgery to Settings UpdateEPSS 0.3%CVE-2024-10685MEDIUMContact Form 7 Redirect & Thank You Page <= 1.0.6 - Reflected Cross-Site ScriptingEPSS 0.3%CVE-2024-13560MEDIUMSubscriptions & Memberships for PayPal <= 1.1.6 - Cross-Site Request Forgery to Arbitrary Post DeletionEPSS 0.3%CVE-2025-10701MEDIUMTime Clock – A WordPress Employee & Volunteer Time Clock Plugin <= 1.3.1 - Authenticated (Custom+) Stored Cross-Site ScriptingEPSS 0.2%CVE-2024-8476MEDIUMEasy PayPal Events <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Post DeletionEPSS 0.2%CVE-2026-9189MEDIUMContact Form 7 – PayPal & Stripe Add-on <= 2.4.9 - Unauthenticated Payment Bypass via Insufficient Verification of Data Authenticity via PayPal IPN Handler ('invoice'/'mc_gross' Verification)EPSS 0.2%CVE-2025-12752MEDIUMSubscriptions & Memberships for PayPal <= 1.1.7 - Unauthenticated Fake Payment CreationEPSS 0.2%CVE-2024-9592MEDIUMEasy PayPal Gift Certificate <= 1.2.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting via wpppgc_plugin_optionsEPSS 0.1%