Krzysztof Zając

2 exploits Active since Mar 2022
CVE-2021-25003 NOMISEC CRITICAL WORKING POC
WPCargo Track & Trace <6.9.0 - RCE
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE
6 stars
CVSS 9.8
CVE-2022-0169 METASPLOIT CRITICAL ruby WORKING POC
WordPress Photo Gallery Plugin SQL Injection (CVE-2022-0169)
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection
CVSS 9.8