mhmrajib Vulnerabilities and Affected Products
Vulnerabilities associated with HM Multiple Roles.
Products
Clear product- WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes3 vulnerabilities
- AidWP – Donation & Payment Forms (Stripe Powered)2 vulnerabilities
- TopNewsWp – Display Tikcer News, RSS Feed Widget and Many More2 vulnerabilities
- HM Multiple Roles1 vulnerability
- JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-4974MEDIUM | Freemius SDK <= 2.4.2 - Missing Authorization ChecksThe Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable. CWE-862Oct 16, 2024 | CVSS6.3v3.1 | EPSS0.442% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |