Khaled_alenazi
30 exploits
Active since Jan 2024
NgocCode WP Load Gallery <2.1.6 - RCE
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal via wfu_file_downloader.php
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Local File Inclusion
Gilblas Ngunte Possi PSW Front-end Login & Registration <1.13 - Inf...
Picsmize <= 1.0.0 - Unauthenticated Arbitrary File Upload
WordPress Really Simple SSL Plugin Authentication Bypass to RCE
GutenKit < 2.1.0 - Unauthenticated Arbitrary File Upload via install-active-plugin Endpoint
nssTheme Wp NssUser Register <1.0.0 - Privilege Escalation
Web Directory Free <1.7.3 - Code Injection
Vayu Blocks - Unauthorized Plugin Installation
Siddharth Nagar Import Export For WooCommerce <1.5 - RCE
CVSS 9.9
Beee ACF City Selector <1.14.0 - RCE
CVSS 6.6
PZ Frontend Manager < 1.0.6 - Cross-Site Request Forgery
CVSS 8.8
User Profile Builder <3.11.8 - Info Disclosure
CVSS 9.1
Tainacan <= 0.21.7 - Authenticated Arbitrary File Read via Missing Authorization in get_file Function
CVSS 6.5
Crafthemes Demo Import <3.3 - File Upload
CVSS 7.2
Hunk Companion <= 1.8.4 - Unauthenticated Arbitrary Plugin Installation and Activation via REST API
CVSS 9.8
Wux Blog Editor <3.0.0 - File Upload
CVSS 9.8
WatchTowerHQ <= 3.10.1 - Unauthenticated Authentication Bypass via Empty OTA Token
CVSS 9.8
WP REST API FNS <= 1.0.0 - Authentication Bypass
CVSS 9.8
WP Query Console <= 1.0 - Remote Code Execution
CVSS 10.0
ThemeHunk Zita Site Builder <1.0.2 - Info Disclosure
CVSS 9.1
WebsiteinWP Blogpoet <= 1.0.3 - Missing Authorization
CVSS 6.5
Hunk Companion WP <1.9.0 - Auth Bypass
CVSS 9.8
Debug Tool < 2.2 - Unauthenticated Arbitrary File Creation via dbt_pull_image()
CVSS 9.8