Boshe99
121 exploits
Active since Nov 2023
Verbalize WP <= 1.0 - Unauthenticated Arbitrary File Upload
CVSS 10.0
Scott Paterson ScottCart <= 1.1 - Remote Code Execution
CVSS 8.3
WP Query Console <= 1.0 - Remote Code Execution
CVSS 10.0
The Novel Design Store Directory <4.3.0 - Unrestricted Upload of Fi...
CVSS 10.0
Webful Creations Computer Repair Shop <3.8115 - RCE
CVSS 10.0
Arttia Creative Datasets Manager <1.5 - RCE
CVSS 10.0
Picsmize <= 1.0.0 - Unauthenticated Arbitrary File Upload
CVSS 10.0
Cliconomics Exclusive Content Password Protect - CSRF
CVSS 9.6
Siddharth Nagar Import Export For WooCommerce <1.5 - RCE
CVSS 9.9
nssTheme Wp NssUser Register <1.0.0 - Privilege Escalation
CVSS 9.8
ThemeHunk Zita Site Builder <1.0.2 - Info Disclosure
CVSS 9.1
Mike Leembruggen Simple Dashboard <2.0 - Privilege Escalation
CVSS 9.8
Webdeclic WPMasterToolKit <1.13.1 - Code Injection
CVSS 9.1
Beee ACF City Selector <1.14.0 - RCE
CVSS 6.6
Pexels: Free Stock Photos <1.2.2 - File Upload
CVSS 8.8
PZ Frontend Manager < 1.0.6 - Cross-Site Request Forgery
CVSS 8.8
User Profile Builder <3.11.8 - Info Disclosure
CVSS 9.1
Grow by Tradedoubler <2.0.21 - Code Injection
CVSS 9.8
Tainacan <= 0.21.7 - Authenticated Arbitrary File Read via Missing Authorization in get_file Function
CVSS 6.5
FileOrganizer - WordPress File Manager <= 1.0.9 - Authenticated Arbitrary File Upload via fileorganizer_ajax_handler
CVSS 7.5
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal via wfu_file_downloader.php
CVSS 9.8
GutenKit < 2.1.0 - Unauthenticated Arbitrary File Upload via install-active-plugin Endpoint
CVSS 9.8
Time Clock and Time Clock Pro <= 1.2.2 - Unauthenticated Remote Code Execution via etimeclockwp_load_function_callback
CVSS 8.3
Crafthemes Demo Import <3.3 - File Upload
CVSS 7.2
WPvivid Migration, Backup, Staging < 0.9.35 - Authenticated Arbitrary File Upload via AJAX Actions
CVSS 8.8