Jonathan Desrosiers
9 exploits
Active since Jun 2020
WordPress < 5.5.2 - Deserialization of Untrusted Data in FilteredIterator
CVSS 9.8
WordPress 3.7-3.7.36 - SQL Injection via WP_Query
CVSS 8.0
WordPress < 5.5.2 - Missing Authorization via XML-RPC Comment
CVSS 9.8
WordPress < 5.5.2 - Remote Code Execution via Improper Installation Check
CVSS 9.8
WordPress < 5.5.2 - Arbitrary File Deletion via Improper Meta Key Protection
CVSS 9.1
WordPress 3.7-5.4.1 - Authenticated Stored Cross-Site Scripting via Media File Attachment
CVSS 6.8
WordPress 3.7-3.7.33 - Open Redirect via URL Sanitization Issue
CVSS 5.7
WordPress 3.7-5.4.1 - Stored Cross-Site Scripting via Theme Folder Name
CVSS 2.4
WordPress 3.7-5.4.1 - Arbitrary User Meta Field Injection via set-screen-option Filter Misuse
CVSS 3.5