RandomRobbieBF
184 exploits
Active since Jun 2017
WordPress Social Login and Register <= 7.6.4 - Authentication Bypass via Insufficient Encryption
Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
GitLab Password Reset Account Takeover
PHPUnit < 4.8.28 and 5.x < 5.6.3 - Remote Code Execution via HTTP POST Data
Time Clock and Time Clock Pro <= 1.2.2 - Unauthenticated Remote Code Execution via etimeclockwp_load_function_callback
WPBot AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via $strid
MStore API < 3.9.2 - Unauthenticated Authentication Bypass via Listing REST API
SoftLab Integrate Google Drive - Info Disclosure
WP REST API FNS <= 1.0.0 - Authentication Bypass
Image horizontal reel scroll slideshow < 13.3 - Authenticated SQL Injection via Shortcode Parameter
Wux Blog Editor <3.0.0 - File Upload
InstaWP Connect <0.1.0.8 - Privilege Escalation
WordPress Really Simple SSL Plugin Authentication Bypass to RCE
Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Option Update via REST Endpoint
WP Query Console <= 1.0 - Remote Code Execution
JSON API User <3.9.3 - Privilege Escalation
WP Popup Builder <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution
SWIT WP Sessions Time Monitoring Full Automatic <1.0.9 - SQL Injection
Qode Essential Addons < 1.5.2 - Arbitrary Plugin Installation and Activation
MonsterInsights < 8.9.1 - Unauthenticated Stored Cross-Site Scripting via Page Title Spoofing
Tareq Hasan Meetup <= 0.1 - Privilege Escalation via Authorization Bypass
WordPress LearnPress Unauthenticated SQLi (CVE-2024-8522, CVE-2024-8529)
GutenKit < 2.1.0 - Unauthenticated Arbitrary File Upload via install-active-plugin Endpoint
WP-Advanced-Search < 3.3.9.2 - Unauthenticated SQL Injection via t Parameter
PDF Generator Addon - Path Traversal