cyberlord92 Vulnerabilities and Affected Products
Vulnerabilities associated with Employee Directory – Staff Directory and Listing.
Products
Clear product- Active Directory Integration / LDAP Integration4 vulnerabilities
- Miniorange OTP Verification with Firebase4 vulnerabilities
- OAuth Single Sign On – SSO (OAuth Client)4 vulnerabilities
- miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)3 vulnerabilities
- Page and Post Restriction3 vulnerabilities
- Broken Link Checker | Finder2 vulnerabilities
- Employee Directory – Staff Directory and Listing2 vulnerabilities
- Integrate Dynamics 365 CRM2 vulnerabilities
- PowerBI Embed Reports2 vulnerabilities
- SAML Single Sign On – SSO Login2 vulnerabilities
- Web Application Firewall – website security2 vulnerabilities
- All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login1 vulnerability
- Login with YourMembership – YM SSO Login1 vulnerability
- login_using_wordpress_users1 vulnerability
- Malware Scanner1 vulnerability
- miniOrange 2FA – Two-Factor Authentication for WordPress (SMS, Email & Google Authenticator)1 vulnerability
- miniOrange OTP Login, Verification and SMS Notifications1 vulnerability
- miniOrange OTP Verification and SMS Notification for WooCommerce1 vulnerability
- Password Policy Manager | Password Manager1 vulnerability
- SAML IDP (Identity Provider) – Login with Website Users1 vulnerability
- Staff/Employee Business Directory for Active Directory1 vulnerability
- User Sync1 vulnerability
- Web3 – Crypto wallet Login & NFT token gating1 vulnerability
- WordPress Single Sign-On (SSO) - Multisite All-Inclusive1 vulnerability
- WordPress Single Sign-On (SSO) - Multisite Enterprise1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-1279MEDIUM | Employee Directory <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_title' Shortcode AttributeThe Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_title' parameter in the `search_employee_directory` shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Feb 6, 2026 | CVSS6.4v3.1 | EPSS0.235% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-8420HIGH | Multiple Plugins by emarket-design <= Multiple Versions - Unauthenticated Limited Remote Code ExecutionMultiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called CWE-95Aug 6, 2025 | CVSS8.1v3.1 | EPSS0.96% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |