RandomRobbieBF
184 exploits
Active since Jun 2017
WebsiteinWP Blogpoet <= 1.0.3 - Missing Authorization
Smackcoders SendGrid for WordPress <= 1.4 - SQL Injection
Relevanssi < 4.22.1 and Relevanssi Premium < 2.25.0 - Unauthenticated Query Log Data Export
Debug Tool < 2.2 - Unauthenticated Arbitrary File Creation via dbt_pull_image()
Relais 2FA plugin <1.0 - Auth Bypass
Hustle - Email Marketing - Info Disclosure
10Web AI Assistant < 1.0.18 - Authenticated Arbitrary Plugin Installation via Missing Capability Check
WordPress Download Mgr <3.2.83 - Info Disclosure
XLPlugins NextMove Lite <2.17.0 - Info Disclosure
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Local File Inclusion
Advanced Form Integration - SQL Injection
ConvertPlus <= 3.5.30 - Authenticated Denial of Service via cp_dismiss_notice AJAX Endpoint
Jordy Meow AI Engine: ChatGPT Chatbot <= 1.9.98 - Unauthenticated Arbitrary File Upload
ThemeIsle Cloud Templates & Patterns collection <= 1.2.2 - Exposure of Sensitive Information via Log File
KD Coming Soon < 1.7 - PHP Object Injection via Untrusted Data Deserialization
HashThemes Square <2.0.0 - Info Disclosure
Formidable Forms <6.2 - Code Injection
Email Subscribers & Newsletters <5.3.2 - SQL Injection
Pie Register < 3.7.1.6 - Unauthenticated User Impersonation via Social Login
CMP by NiteoThemes <= 3.8.1 - Unauthenticated Authorization Bypass
WP Email Users <1.7.6 - SQL Injection
MapPress < 2.53.9 - Unauthenticated Remote Code Execution via AJAX Function
PHPUnit < 4.8.28 and 5.x < 5.6.3 - Remote Code Execution via HTTP POST Data
CVSS 9.8
Yoast SEO <= 22.5 - Unauthenticated Reflected Cross-Site Scripting via URL Parameter
CVSS 6.1
Events Manager <= 7.0.3 - Unauthenticated Time-Based SQL Injection via Orderby Parameter
CVSS 7.5