Boshe99
121 exploits
Active since Nov 2023
StellarWP Membership Plugin - Restrict Content <= 3.2.7 - Exposure of Sensitive Information via Log File
CVSS 5.3
Jordy Meow AI Engine: ChatGPT Chatbot <= 1.9.98 - Unauthenticated Arbitrary File Upload
CVSS 10.0
EventON WordPress Plugin < 2.2.7 - Unauthenticated Email Address Disclosure via AJAX Action
CVSS 5.3
Vayu Blocks - Unauthorized Plugin Installation
CVSS 9.8
Pubnews theme <1.0.7 - Privilege Escalation
CVSS 8.8
Debug Tool < 2.2 - Unauthenticated Arbitrary File Creation via dbt_pull_image()
CVSS 9.8
GPX Viewer <= 2.2.9 - Authenticated Arbitrary File Creation via gpxv_file_upload()
CVSS 8.8
Top Store theme <1.5.4 - Privilege Escalation
CVSS 8.8
Th Shop Mania <1.4.9 - Privilege Escalation
CVSS 8.8
WordPress Really Simple SSL Plugin Authentication Bypass to RCE
CVSS 9.8
Hunk Companion WP <1.9.0 - Auth Bypass
CVSS 9.8
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Local File Inclusion
CVSS 9.8
SEO LAT Auto Post <= 2.2.1 - Unauthenticated File Overwrite and Remote Code Execution via remote_update AJAX Action
CVSS 9.8
Concrete CMS 9.0.0-9.2.4 - Stored Cross-Site Scripting via Role Name Field
CVSS 2.0
linkID WordPress <0.1.2 - Info Disclosure
CVSS 8.6
WP BASE Booking <4.9.2 - Info Disclosure
CVSS 6.5
Error Log Viewer By WP Guru <1.0.1.3 - Info Disclosure
CVSS 7.5
XLPlugins NextMove Lite <2.17.0 - Info Disclosure
CVSS 8.8
InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
CVSS 9.8
XLPlugins Finale Lite < 2.18.0 - Unauthenticated Arbitrary Plugin Installation and Activation
CVSS 8.8
biplob018 Shortcode Addons <3.2.5 - RCE
CVSS 9.1
Web Directory Free <1.7.3 - Code Injection
CVSS 9.1
WebsiteinWP Blogpoet <= 1.0.3 - Missing Authorization
CVSS 6.5
WP REST API FNS <= 1.0.0 - Authentication Bypass
CVSS 9.8
WPvivid Migration, Backup, Staging < 0.9.35 - Authenticated Arbitrary File Upload via AJAX Actions
CVSS 8.8