Khaled Alenazi
54 exploits
Active since Mar 2024
Webdeclic WPMasterToolKit <1.13.1 - Code Injection
Order Attachments for WooCommerce 2.0-2.4.1 - Authenticated Arbitrary File Upload via wcoa_add_attachment AJAX Action
Verbalize WP <= 1.0 - Unauthenticated Arbitrary File Upload
Scott Paterson ScottCart <= 1.1 - Remote Code Execution
XLPlugins Finale Lite < 2.18.0 - Unauthenticated Arbitrary Plugin Installation and Activation
SEO LAT Auto Post <= 2.2.1 - Unauthenticated File Overwrite and Remote Code Execution via remote_update AJAX Action
Top Store theme <1.5.4 - Privilege Escalation
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
CVSS 9.8
WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering
CVSS 8.1
WordPress User Registration & Membership Plugin <=5.1.2 - Privilege Escalation
CVSS 9.8
Academy LMS - WordPress LMS Plugin <3.5.0 - Privilege Escalation
CVSS 9.8
WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Privilege Escalation vulnerability
CVSS 9.8
Simple Business Directory Pro - Privilege Escalation
CVSS 9.8
WPvivid Backup & Migration <0.9.123 - Unauthenticated RCE
CVSS 9.8
Imithemes Real Spaces - WordPress Properties Directory Theme <= 3.6 - Privilege Escalation
CVSS 9.8
Nirmal Kumar Ram WP Remote Thumbnail <1.3.1 - RCE
CVSS 9.9
WP Directory Kit <= 1.4.4 - Unauthenticated Authentication Bypass via Weak Auto-Login Token
CVSS 10.0
SoJ SoundSlides <= 1.2.2 - Authenticated Arbitrary File Upload via soj_soundslides_options_subpanel()
CVSS 8.8
Motors Plugin <= 1.4.64 - Authenticated Arbitrary Plugin Installation
CVSS 8.8
Rometheme RomethemeKit For Elementor <1.5.4 - Code Injection
CVSS 9.9
Anant Addons for Elementor <1.1.5 - CSRF
CVSS 9.6
RomanCode MapSVG Lite <8.5.34 - RCE
CVSS 9.9
Portfolleo <= 1.2 - Unauthenticated Arbitrary File Upload
CVSS 9.9
Mike Leembruggen Simple Dashboard <2.0 - Privilege Escalation
CVSS 9.8
Arttia Creative Datasets Manager <1.5 - RCE
CVSS 10.0