Ivan Spiridonov - xbz0n

3 exploits Active since Feb 2024
CVE-2024-0399 NOMISEC HIGH WORKING POC
Vanquish Woocommerce Customers Manager < 29.7 - SQL Injection
The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.
1 stars
CVSS 8.1
CVE-2024-0566 NOMISEC HIGH WORKING POC
Smart Manager WP <8.28.0 - SQL Injection
The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
1 stars
CVSS 7.2
CVE-2024-0399 EXPLOITDB HIGH text WORKING POC
Vanquish Woocommerce Customers Manager < 29.7 - SQL Injection
The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.
CVSS 8.1