Yucaerin
17 exploits
Active since Jan 2025
TemplateInvaders TI WooCommerce Wishlist <2.10.0 - Code Injection
WordPress Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - File Upload Code Execution
Invoice Ninja < 5.10.43 - Unauthenticated Remote Code Execution via Route Hash Deserialization
Alone - Charity Multipurpose Non-profit WordPress Theme <7.8.3 - RCE
Writebot AI Content Generator <4.0.0 - Privilege Escalation
Motors WordPress <5.6.67 - Privilege Escalation
Kubio AI Page Builder <2.5.1 - Local File Inclusion
Doctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation
CVSS 9.8
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
CVSS 9.8
Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'
CVSS 9.8
Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process
CVSS 9.8
RH - Real Estate WordPress Theme <4.4.0 - Privilege Escalation
CVSS 8.8
Uxper Sala - Startup & SaaS WordPress Theme <=1.1.4 - Privilege Escalation via Account Takeover
CVSS 9.8
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
CVSS 7.5
Crawlomatic Multipage Scraper Post Generator <2.6.8.1 - File Upload
CVSS 9.8
Eventin plugin <4.0.26 - Info Disclosure
CVSS 7.5
Order Delivery Date Pro for WooCommerce < 12.3.1 - Arbitrary Option Update
CVSS 9.8