Khaled Alenazi
49 exploits
Active since Mar 2024
Order Attachments for WooCommerce 2.0-2.4.1 - Authenticated Arbitrary File Upload via wcoa_add_attachment AJAX Action
Cliconomics Exclusive Content Password Protect - CSRF
XLPlugins Finale Lite < 2.18.0 - Unauthenticated Arbitrary Plugin Installation and Activation
Top Store theme <1.5.4 - Privilege Escalation
SEO LAT Auto Post <= 2.2.1 - Unauthenticated File Overwrite and Remote Code Execution via remote_update AJAX Action
Academy LMS - WordPress LMS Plugin <3.5.0 - Privilege Escalation
CVSS 9.8
Simple Business Directory Pro - Privilege Escalation
CVSS 9.8
WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Privilege Escalation vulnerability
CVSS 9.8
WPvivid Backup & Migration <0.9.123 - Unauthenticated RCE
CVSS 9.8
Imithemes Real Spaces - WordPress Properties Directory Theme <= 3.6 - Privilege Escalation
CVSS 9.8
WP Directory Kit <= 1.4.4 - Unauthenticated Authentication Bypass via Weak Auto-Login Token
CVSS 10.0
Anant Addons for Elementor <1.1.5 - CSRF
CVSS 9.6
RomanCode MapSVG Lite <8.5.34 - RCE
CVSS 9.9
Motors Plugin <= 1.4.64 - Authenticated Arbitrary Plugin Installation
CVSS 8.8
Nirmal Kumar Ram WP Remote Thumbnail <1.3.1 - RCE
CVSS 9.9
Rometheme RomethemeKit For Elementor <1.5.4 - Code Injection
CVSS 9.9
SoJ SoundSlides <= 1.2.2 - Authenticated Arbitrary File Upload via soj_soundslides_options_subpanel()
CVSS 8.8
Portfolleo <= 1.2 - Unauthenticated Arbitrary File Upload
CVSS 9.9
Mike Leembruggen Simple Dashboard <2.0 - Privilege Escalation
CVSS 9.8
Arttia Creative Datasets Manager <1.5 - RCE
CVSS 10.0
biplob018 Shortcode Addons <3.2.5 - RCE
CVSS 9.1
GPX Viewer <= 2.2.9 - Authenticated Arbitrary File Creation via gpxv_file_upload()
CVSS 8.8
Th Shop Mania <1.4.9 - Privilege Escalation
CVSS 8.8
Pubnews theme <1.0.7 - Privilege Escalation
CVSS 8.8