biulove0x

3 exploits Active since Mar 2022
CVE-2022-0441 NOMISEC CRITICAL WORKING POC
MasterStudy LMS <2.7.6 - Info Disclosure
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
6 stars
CVSS 9.8
CVE-2021-25003 NOMISEC CRITICAL WORKING POC
WPCargo Track & Trace <6.9.0 - RCE
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE
6 stars
CVSS 9.8
CVE-2022-1903 NOMISEC HIGH WORKING POC
ARMember <3.4.8 - Auth Bypass
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username
1 stars
CVSS 8.1