diff --git a/internal/data/assets/plugin_656173792d6163636f7264696f6e2d66726565811c9dc5_gen.json b/internal/data/assets/plugin_656173792d6163636f7264696f6e2d66726565811c9dc5_gen.json index 3b0aaa39..15f0b791 100644 --- a/internal/data/assets/plugin_656173792d6163636f7264696f6e2d66726565811c9dc5_gen.json +++ b/internal/data/assets/plugin_656173792d6163636f7264696f6e2d66726565811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/1dab93f3-8068-4655-aa3d-a9f4c8dc9d61/easy-accordion-free","title":"Easy Accordion <= 2.1.20 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"1dab93f3-8068-4655-aa3d-a9f4c8dc9d61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1dab93f3-8068-4655-aa3d-a9f4c8dc9d61?source=api-prod","cve":"CVE-2022-4487","affectedVersions":"<=2.1.20","severity":"medium"},{"advisoryId":"WPSECADV/WF/7c4f9958-0e5a-483c-926e-ceaee00ffa45/easy-accordion-free","title":"Easy Accordion <= 2.0.21 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-09-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"7c4f9958-0e5a-483c-926e-ceaee00ffa45"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7c4f9958-0e5a-483c-926e-ceaee00ffa45?source=api-prod","cve":"CVE-2021-24576","affectedVersions":"<=2.0.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/88f2fa28-5bb2-4633-b2bc-27cc6a4e304c/easy-accordion-free","title":"Easy Accordion – Best Accordion FAQ Plugin for WordPress <= 2.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"88f2fa28-5bb2-4633-b2bc-27cc6a4e304c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/88f2fa28-5bb2-4633-b2bc-27cc6a4e304c?source=api-prod","cve":"CVE-2024-1363","affectedVersions":"<=2.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/eb0fb0a7-b9f7-42db-b826-fc09090bd817/easy-accordion-free","title":"Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-15 13:50:50","sources":[{"name":"Wordfence","remoteId":"eb0fb0a7-b9f7-42db-b826-fc09090bd817"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eb0fb0a7-b9f7-42db-b826-fc09090bd817?source=api-prod","cve":"CVE-2026-15652","affectedVersions":"<=3.1.6","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/1dab93f3-8068-4655-aa3d-a9f4c8dc9d61/easy-accordion-free","title":"Easy Accordion <= 2.1.20 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"1dab93f3-8068-4655-aa3d-a9f4c8dc9d61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1dab93f3-8068-4655-aa3d-a9f4c8dc9d61?source=api-prod","cve":"CVE-2022-4487","affectedVersions":"<=2.1.20","severity":"medium"},{"advisoryId":"WPSECADV/WF/6a8a5b2b-6cb0-48bf-ba03-d23b1624390d/easy-accordion-free","title":"Easy Accordion <= 3.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-08-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"6a8a5b2b-6cb0-48bf-ba03-d23b1624390d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6a8a5b2b-6cb0-48bf-ba03-d23b1624390d?source=api-prod","cve":"CVE-2026-18988","affectedVersions":"<=3.1.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/7c4f9958-0e5a-483c-926e-ceaee00ffa45/easy-accordion-free","title":"Easy Accordion <= 2.0.21 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-09-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"7c4f9958-0e5a-483c-926e-ceaee00ffa45"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7c4f9958-0e5a-483c-926e-ceaee00ffa45?source=api-prod","cve":"CVE-2021-24576","affectedVersions":"<=2.0.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/88f2fa28-5bb2-4633-b2bc-27cc6a4e304c/easy-accordion-free","title":"Easy Accordion – Best Accordion FAQ Plugin for WordPress <= 2.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"88f2fa28-5bb2-4633-b2bc-27cc6a4e304c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/88f2fa28-5bb2-4633-b2bc-27cc6a4e304c?source=api-prod","cve":"CVE-2024-1363","affectedVersions":"<=2.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/eb0fb0a7-b9f7-42db-b826-fc09090bd817/easy-accordion-free","title":"Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-15 13:50:50","sources":[{"name":"Wordfence","remoteId":"eb0fb0a7-b9f7-42db-b826-fc09090bd817"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eb0fb0a7-b9f7-42db-b826-fc09090bd817?source=api-prod","cve":"CVE-2026-15652","affectedVersions":"<=3.1.6","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6d696e696f72616e67652d6c6f67696e2d6f70656e6964811c9dc5_gen.json b/internal/data/assets/plugin_6d696e696f72616e67652d6c6f67696e2d6f70656e6964811c9dc5_gen.json index e0d1aece..823a0f0a 100644 --- a/internal/data/assets/plugin_6d696e696f72616e67652d6c6f67696e2d6f70656e6964811c9dc5_gen.json +++ b/internal/data/assets/plugin_6d696e696f72616e67652d6c6f67696e2d6f70656e6964811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/021a25c9-7fad-425f-8104-bb4852603613/miniorange-login-openid","title":"WordPress Social Login and Register <= 7.6.0 - Missing Authorization to Unauthenticated Arbitrary Content Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"021a25c9-7fad-425f-8104-bb4852603613"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/021a25c9-7fad-425f-8104-bb4852603613?source=api-prod","cve":"CVE-2023-25455","affectedVersions":"<=7.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/08ca186a-2486-4a58-9c53-03e9eba13e66/miniorange-login-openid","title":"WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"08ca186a-2486-4a58-9c53-03e9eba13e66"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/08ca186a-2486-4a58-9c53-03e9eba13e66?source=api-prod","cve":"CVE-2023-2982","affectedVersions":"<=7.6.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/17735732-a6c4-4d84-8b8c-c1730b887e8f/miniorange-login-openid","title":"WordPress Social Login and Register <= 7.6.10 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"17735732-a6c4-4d84-8b8c-c1730b887e8f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/17735732-a6c4-4d84-8b8c-c1730b887e8f?source=api-prod","cve":"CVE-2025-47670","affectedVersions":"<=7.6.10","severity":"high"},{"advisoryId":"WPSECADV/WF/1ffb9a8e-b08f-451b-bdb5-268d7b618b66/miniorange-login-openid","title":"WordPress Social Login and Register <=7.5.12 - Missing Authorization to Plugin Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"1ffb9a8e-b08f-451b-bdb5-268d7b618b66"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1ffb9a8e-b08f-451b-bdb5-268d7b618b66?source=api-prod","cve":"CVE-2023-24375","affectedVersions":"=7.5.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/45668368-5846-41bb-b862-dfeb283e83cf/miniorange-login-openid","title":"WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.6 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"45668368-5846-41bb-b862-dfeb283e83cf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/45668368-5846-41bb-b862-dfeb283e83cf?source=api-prod","cve":"CVE-2023-47683","affectedVersions":"<=7.6.6","severity":"high"},{"advisoryId":"WPSECADV/WF/4af762d6-bc93-4724-b27d-4873a8bb4f38/miniorange-login-openid","title":"miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"4af762d6-bc93-4724-b27d-4873a8bb4f38"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4af762d6-bc93-4724-b27d-4873a8bb4f38?source=api-prod","cve":"CVE-2026-65561","affectedVersions":"<=7.8.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/a56b59ce-29c2-4172-b703-a06d7bb28da0/miniorange-login-openid","title":"miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP Flow\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-10 07:45:14","sources":[{"name":"Wordfence","remoteId":"a56b59ce-29c2-4172-b703-a06d7bb28da0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a56b59ce-29c2-4172-b703-a06d7bb28da0?source=api-prod","cve":"CVE-2026-12761","affectedVersions":"<=7.7.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/b10c7619-85b0-4d06-b48c-248fa3f66229/miniorange-login-openid","title":"Social Login and Register <= 7.7.0 - Authenticated (Administrator+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"b10c7619-85b0-4d06-b48c-248fa3f66229"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b10c7619-85b0-4d06-b48c-248fa3f66229?source=api-prod","cve":"CVE-2025-68974","affectedVersions":"<=7.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca91046d-61c1-4a65-a078-c7dffb27092c/miniorange-login-openid","title":"WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.5.14 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca91046d-61c1-4a65-a078-c7dffb27092c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca91046d-61c1-4a65-a078-c7dffb27092c?source=api-prod","cve":"CVE-2023-23710","affectedVersions":"<=7.5.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/f677b257-606a-45f2-ba85-3a56b8df2a3c/miniorange-login-openid","title":"miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon <= 200.3.9 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"f677b257-606a-45f2-ba85-3a56b8df2a3c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f677b257-606a-45f2-ba85-3a56b8df2a3c?source=api-prod","cve":"CVE-2024-11087","affectedVersions":"<=200.3.9","severity":"high"},{"advisoryId":"WPSECADV/WF/faac24e5-94f2-40e5-932e-93ddc2c8af7c/miniorange-login-openid","title":"WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.5.14 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"faac24e5-94f2-40e5-932e-93ddc2c8af7c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/faac24e5-94f2-40e5-932e-93ddc2c8af7c?source=api-prod","cve":"CVE-2023-23706","affectedVersions":"<=7.5.14","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/021a25c9-7fad-425f-8104-bb4852603613/miniorange-login-openid","title":"WordPress Social Login and Register <= 7.6.0 - Missing Authorization to Unauthenticated Arbitrary Content Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"021a25c9-7fad-425f-8104-bb4852603613"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/021a25c9-7fad-425f-8104-bb4852603613?source=api-prod","cve":"CVE-2023-25455","affectedVersions":"<=7.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/08ca186a-2486-4a58-9c53-03e9eba13e66/miniorange-login-openid","title":"WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"08ca186a-2486-4a58-9c53-03e9eba13e66"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/08ca186a-2486-4a58-9c53-03e9eba13e66?source=api-prod","cve":"CVE-2023-2982","affectedVersions":"<=7.6.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/17735732-a6c4-4d84-8b8c-c1730b887e8f/miniorange-login-openid","title":"WordPress Social Login and Register <= 7.6.10 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"17735732-a6c4-4d84-8b8c-c1730b887e8f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/17735732-a6c4-4d84-8b8c-c1730b887e8f?source=api-prod","cve":"CVE-2025-47670","affectedVersions":"<=7.6.10","severity":"high"},{"advisoryId":"WPSECADV/WF/1ffb9a8e-b08f-451b-bdb5-268d7b618b66/miniorange-login-openid","title":"WordPress Social Login and Register <=7.5.12 - Missing Authorization to Plugin Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"1ffb9a8e-b08f-451b-bdb5-268d7b618b66"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1ffb9a8e-b08f-451b-bdb5-268d7b618b66?source=api-prod","cve":"CVE-2023-24375","affectedVersions":"=7.5.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/2fa6d06d-7323-42d1-94ef-9dfda9c166c4/miniorange-login-openid","title":"miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) < 7.8.0 - Unauthenticated Privilege Escalation via Account Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"2fa6d06d-7323-42d1-94ef-9dfda9c166c4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2fa6d06d-7323-42d1-94ef-9dfda9c166c4?source=api-prod","cve":"CVE-2026-14300","affectedVersions":"<7.8.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/45668368-5846-41bb-b862-dfeb283e83cf/miniorange-login-openid","title":"WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.6 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"45668368-5846-41bb-b862-dfeb283e83cf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/45668368-5846-41bb-b862-dfeb283e83cf?source=api-prod","cve":"CVE-2023-47683","affectedVersions":"<=7.6.6","severity":"high"},{"advisoryId":"WPSECADV/WF/4af762d6-bc93-4724-b27d-4873a8bb4f38/miniorange-login-openid","title":"miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"4af762d6-bc93-4724-b27d-4873a8bb4f38"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4af762d6-bc93-4724-b27d-4873a8bb4f38?source=api-prod","cve":"CVE-2026-65561","affectedVersions":"<=7.8.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/a56b59ce-29c2-4172-b703-a06d7bb28da0/miniorange-login-openid","title":"miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP Flow\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-10 07:45:14","sources":[{"name":"Wordfence","remoteId":"a56b59ce-29c2-4172-b703-a06d7bb28da0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a56b59ce-29c2-4172-b703-a06d7bb28da0?source=api-prod","cve":"CVE-2026-12761","affectedVersions":"<=7.7.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/b10c7619-85b0-4d06-b48c-248fa3f66229/miniorange-login-openid","title":"Social Login and Register <= 7.7.0 - Authenticated (Administrator+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"b10c7619-85b0-4d06-b48c-248fa3f66229"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b10c7619-85b0-4d06-b48c-248fa3f66229?source=api-prod","cve":"CVE-2025-68974","affectedVersions":"<=7.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca91046d-61c1-4a65-a078-c7dffb27092c/miniorange-login-openid","title":"WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.5.14 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca91046d-61c1-4a65-a078-c7dffb27092c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca91046d-61c1-4a65-a078-c7dffb27092c?source=api-prod","cve":"CVE-2023-23710","affectedVersions":"<=7.5.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/f677b257-606a-45f2-ba85-3a56b8df2a3c/miniorange-login-openid","title":"miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon <= 200.3.9 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"f677b257-606a-45f2-ba85-3a56b8df2a3c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f677b257-606a-45f2-ba85-3a56b8df2a3c?source=api-prod","cve":"CVE-2024-11087","affectedVersions":"<=200.3.9","severity":"high"},{"advisoryId":"WPSECADV/WF/faac24e5-94f2-40e5-932e-93ddc2c8af7c/miniorange-login-openid","title":"WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.5.14 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"faac24e5-94f2-40e5-932e-93ddc2c8af7c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/faac24e5-94f2-40e5-932e-93ddc2c8af7c?source=api-prod","cve":"CVE-2023-23706","affectedVersions":"<=7.5.14","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7765622d6469726563746f72792d66726565811c9dc5_gen.json b/internal/data/assets/plugin_7765622d6469726563746f72792d66726565811c9dc5_gen.json index 2e5a4c50..5efe1e09 100644 --- a/internal/data/assets/plugin_7765622d6469726563746f72792d66726565811c9dc5_gen.json +++ b/internal/data/assets/plugin_7765622d6469726563746f72792d66726565811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/00f7a207-2dc0-4322-a23d-7cd2eb10c21e/web-directory-free","title":"Web Directory Free <= 1.7.12 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"00f7a207-2dc0-4322-a23d-7cd2eb10c21e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00f7a207-2dc0-4322-a23d-7cd2eb10c21e?source=api-prod","cve":"CVE-2025-69018","affectedVersions":"<=1.7.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/1e1e8486-22ed-4034-bdfc-6c9f0e2fbc95/web-directory-free","title":"Web Directory Free <= 1.7.6 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1e1e8486-22ed-4034-bdfc-6c9f0e2fbc95"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1e1e8486-22ed-4034-bdfc-6c9f0e2fbc95?source=api-prod","cve":"CVE-2025-28904","affectedVersions":"<=1.7.6","severity":"high"},{"advisoryId":"WPSECADV/WF/2a6c5610-ed84-4d7d-a28f-d3807230e119/web-directory-free","title":"Web Directory Free <= 1.6.9 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"2a6c5610-ed84-4d7d-a28f-d3807230e119"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2a6c5610-ed84-4d7d-a28f-d3807230e119?source=api-prod","cve":"CVE-2024-3552","affectedVersions":"<=1.6.9","severity":"critical"},{"advisoryId":"WPSECADV/WF/b7ea6312-2703-47d1-909e-8c5fd05d9929/web-directory-free","title":"Web Directory Free <= 1.7.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"b7ea6312-2703-47d1-909e-8c5fd05d9929"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b7ea6312-2703-47d1-909e-8c5fd05d9929?source=api-prod","cve":"CVE-2024-47379","affectedVersions":"<=1.7.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/bada2872-aa45-41a7-aa52-c0be1c3f2b59/web-directory-free","title":"Web Directory Free <= 1.7.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"bada2872-aa45-41a7-aa52-c0be1c3f2b59"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bada2872-aa45-41a7-aa52-c0be1c3f2b59?source=api-prod","cve":"CVE-2025-39567","affectedVersions":"<=1.7.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/d80ab1a4-19f9-4fea-87b4-1d2ba465e860/web-directory-free","title":"Web Directory Free <= 1.7.2 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"d80ab1a4-19f9-4fea-87b4-1d2ba465e860"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d80ab1a4-19f9-4fea-87b4-1d2ba465e860?source=api-prod","cve":"CVE-2024-3673","affectedVersions":"<=1.7.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/d831fa81-4714-4757-b75d-0a8f5edda910/web-directory-free","title":"Web Directory Free <= 1.6.8 - Authenticated (Contributor+) SQL Injection via post_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"d831fa81-4714-4757-b75d-0a8f5edda910"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d831fa81-4714-4757-b75d-0a8f5edda910?source=api-prod","cve":"CVE-2023-2201","affectedVersions":"<=1.6.8","severity":"high"},{"advisoryId":"WPSECADV/WF/e621c82c-ab35-4188-a592-03c09b70f0ae/web-directory-free","title":"Web Directory Free <= 1.7.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"e621c82c-ab35-4188-a592-03c09b70f0ae"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e621c82c-ab35-4188-a592-03c09b70f0ae?source=api-prod","cve":"CVE-2024-3669","affectedVersions":"<=1.7.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f7485859-c155-4335-aa76-3b4363dbbe4c/web-directory-free","title":"Web Directory Free <= 1.7.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"f7485859-c155-4335-aa76-3b4363dbbe4c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f7485859-c155-4335-aa76-3b4363dbbe4c?source=api-prod","cve":"CVE-2025-30908","affectedVersions":"<=1.7.6","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/00f7a207-2dc0-4322-a23d-7cd2eb10c21e/web-directory-free","title":"Web Directory Free <= 1.7.12 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"00f7a207-2dc0-4322-a23d-7cd2eb10c21e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00f7a207-2dc0-4322-a23d-7cd2eb10c21e?source=api-prod","cve":"CVE-2025-69018","affectedVersions":"<=1.7.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/1e1e8486-22ed-4034-bdfc-6c9f0e2fbc95/web-directory-free","title":"Web Directory Free <= 1.7.6 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1e1e8486-22ed-4034-bdfc-6c9f0e2fbc95"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1e1e8486-22ed-4034-bdfc-6c9f0e2fbc95?source=api-prod","cve":"CVE-2025-28904","affectedVersions":"<=1.7.6","severity":"high"},{"advisoryId":"WPSECADV/WF/2a6c5610-ed84-4d7d-a28f-d3807230e119/web-directory-free","title":"Web Directory Free <= 1.6.9 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"2a6c5610-ed84-4d7d-a28f-d3807230e119"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2a6c5610-ed84-4d7d-a28f-d3807230e119?source=api-prod","cve":"CVE-2024-3552","affectedVersions":"<=1.6.9","severity":"critical"},{"advisoryId":"WPSECADV/WF/7320421b-6b88-452d-a363-a71cdf7953a6/web-directory-free","title":"Web Directory Free <= 1.7.13 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-27 21:29:21","sources":[{"name":"Wordfence","remoteId":"7320421b-6b88-452d-a363-a71cdf7953a6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7320421b-6b88-452d-a363-a71cdf7953a6?source=api-prod","cve":"CVE-2026-14785","affectedVersions":"<=1.7.13","severity":"high"},{"advisoryId":"WPSECADV/WF/b7ea6312-2703-47d1-909e-8c5fd05d9929/web-directory-free","title":"Web Directory Free <= 1.7.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"b7ea6312-2703-47d1-909e-8c5fd05d9929"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b7ea6312-2703-47d1-909e-8c5fd05d9929?source=api-prod","cve":"CVE-2024-47379","affectedVersions":"<=1.7.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/bada2872-aa45-41a7-aa52-c0be1c3f2b59/web-directory-free","title":"Web Directory Free <= 1.7.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"bada2872-aa45-41a7-aa52-c0be1c3f2b59"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bada2872-aa45-41a7-aa52-c0be1c3f2b59?source=api-prod","cve":"CVE-2025-39567","affectedVersions":"<=1.7.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/d80ab1a4-19f9-4fea-87b4-1d2ba465e860/web-directory-free","title":"Web Directory Free <= 1.7.2 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"d80ab1a4-19f9-4fea-87b4-1d2ba465e860"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d80ab1a4-19f9-4fea-87b4-1d2ba465e860?source=api-prod","cve":"CVE-2024-3673","affectedVersions":"<=1.7.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/d831fa81-4714-4757-b75d-0a8f5edda910/web-directory-free","title":"Web Directory Free <= 1.6.8 - Authenticated (Contributor+) SQL Injection via post_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"d831fa81-4714-4757-b75d-0a8f5edda910"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d831fa81-4714-4757-b75d-0a8f5edda910?source=api-prod","cve":"CVE-2023-2201","affectedVersions":"<=1.6.8","severity":"high"},{"advisoryId":"WPSECADV/WF/e621c82c-ab35-4188-a592-03c09b70f0ae/web-directory-free","title":"Web Directory Free <= 1.7.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"e621c82c-ab35-4188-a592-03c09b70f0ae"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e621c82c-ab35-4188-a592-03c09b70f0ae?source=api-prod","cve":"CVE-2024-3669","affectedVersions":"<=1.7.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f7485859-c155-4335-aa76-3b4363dbbe4c/web-directory-free","title":"Web Directory Free <= 1.7.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"f7485859-c155-4335-aa76-3b4363dbbe4c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f7485859-c155-4335-aa76-3b4363dbbe4c?source=api-prod","cve":"CVE-2025-30908","affectedVersions":"<=1.7.6","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77702d757365722d66726f6e74656e64811c9dc5_gen.json b/internal/data/assets/plugin_77702d757365722d66726f6e74656e64811c9dc5_gen.json index 47b5ed2e..95058be3 100644 --- a/internal/data/assets/plugin_77702d757365722d66726f6e74656e64811c9dc5_gen.json +++ b/internal/data/assets/plugin_77702d757365722d66726f6e74656e64811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0049583a-0ad3-45e4-a29e-4b8c33d09857/wp-user-frontend","title":"User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-08 19:22:00","sources":[{"name":"Wordfence","remoteId":"0049583a-0ad3-45e4-a29e-4b8c33d09857"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0049583a-0ad3-45e4-a29e-4b8c33d09857?source=api-prod","cve":"CVE-2026-12406","affectedVersions":"<=4.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/09e5391d-2671-4bb4-9adc-29b5fdb59240/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"09e5391d-2671-4bb4-9adc-29b5fdb59240"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/09e5391d-2671-4bb4-9adc-29b5fdb59240?source=api-prod","cve":"CVE-2026-24364","affectedVersions":"<=4.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/1e2b99ac-62f4-4180-aabe-91a5c717ea71/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration <= 4.3.7 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-06-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"1e2b99ac-62f4-4180-aabe-91a5c717ea71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1e2b99ac-62f4-4180-aabe-91a5c717ea71?source=api-prod","cve":"CVE-2026-57334","affectedVersions":"<=4.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/2b5d27cc-c6eb-4c5c-8ee1-30483b91c6fd/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Authenticated (Subscriber+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-07 19:58:37","sources":[{"name":"Wordfence","remoteId":"2b5d27cc-c6eb-4c5c-8ee1-30483b91c6fd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b5d27cc-c6eb-4c5c-8ee1-30483b91c6fd?source=api-prod","cve":"CVE-2026-5127","affectedVersions":"<=4.3.1","severity":"high"},{"advisoryId":"WPSECADV/WF/2c358cbe-7600-43a1-94a3-1530cdb5a9f3/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Authenticated (Author+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-26 06:37:58","sources":[{"name":"Wordfence","remoteId":"2c358cbe-7600-43a1-94a3-1530cdb5a9f3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2c358cbe-7600-43a1-94a3-1530cdb5a9f3?source=api-prod","cve":"CVE-2026-1565","affectedVersions":"<=4.2.8","severity":"high"},{"advisoryId":"WPSECADV/WF/31de3c9b-068d-47d8-9811-feae07f2e9d0/wp-user-frontend","title":"WP User Frontend <= 3.6.5 - Authenticated (Author+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"31de3c9b-068d-47d8-9811-feae07f2e9d0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/31de3c9b-068d-47d8-9811-feae07f2e9d0?source=api-prod","cve":"CVE-2023-47682","affectedVersions":"<=3.6.5","severity":"high"},{"advisoryId":"WPSECADV/WF/379a5016-3968-4b28-8d6e-0f517e419016/wp-user-frontend","title":"Various Plugins <= Various Version - Use of Polyfill.io\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"379a5016-3968-4b28-8d6e-0f517e419016"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/379a5016-3968-4b28-8d6e-0f517e419016?source=api-prod","affectedVersions":"<=4.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/3c476263-72b7-48f1-8ba3-91d69eae7b6a/wp-user-frontend","title":"WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPress < 3.5.25 - Authenticated (Admin+) SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"3c476263-72b7-48f1-8ba3-91d69eae7b6a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3c476263-72b7-48f1-8ba3-91d69eae7b6a?source=api-prod","affectedVersions":"<3.5.25","severity":"high"},{"advisoryId":"WPSECADV/WF/4a0f77ca-2fb5-4e73-a0fa-dfbeb39fbd84/wp-user-frontend","title":"WP User Frontend <= 3.5.28 - Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"4a0f77ca-2fb5-4e73-a0fa-dfbeb39fbd84"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4a0f77ca-2fb5-4e73-a0fa-dfbeb39fbd84?source=api-prod","cve":"CVE-2021-24649","affectedVersions":"<=3.5.28","severity":"high"},{"advisoryId":"WPSECADV/WF/6844c9a6-b25a-4ae1-96f6-023c1df80ddf/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"6844c9a6-b25a-4ae1-96f6-023c1df80ddf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6844c9a6-b25a-4ae1-96f6-023c1df80ddf?source=api-prod","cve":"CVE-2026-42412","affectedVersions":"<=4.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/6e95b16f-a25a-45c7-a875-2d34a1e127ce/wp-user-frontend","title":"WP User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-01 13:23:01","sources":[{"name":"Wordfence","remoteId":"6e95b16f-a25a-45c7-a875-2d34a1e127ce"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6e95b16f-a25a-45c7-a875-2d34a1e127ce?source=api-prod","cve":"CVE-2025-14047","affectedVersions":"<=4.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/84003388-c47c-41db-8d2d-4643aa375a89/wp-user-frontend","title":"Appsero <= 1.2.1 - Missing Authorization\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"84003388-c47c-41db-8d2d-4643aa375a89"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/84003388-c47c-41db-8d2d-4643aa375a89?source=api-prod","affectedVersions":"<=3.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/8a2186c9-fa27-4d7d-be41-c82711c49334/wp-user-frontend","title":"WP User Frontend < 2.3.11 - Arbitrary File Upload\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-02-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"8a2186c9-fa27-4d7d-be41-c82711c49334"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8a2186c9-fa27-4d7d-be41-c82711c49334?source=api-prod","affectedVersions":"<2.3.11","severity":"critical"},{"advisoryId":"WPSECADV/WF/8e8e967f-f627-4c0c-ac0f-0a66ae25c602/wp-user-frontend","title":"WP User Frontend <= 3.6.8 - Missing Authorization via AJAX actions\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e8e967f-f627-4c0c-ac0f-0a66ae25c602"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e8e967f-f627-4c0c-ac0f-0a66ae25c602?source=api-prod","cve":"CVE-2023-45002","affectedVersions":"<=3.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/8f66e25f-b67e-4227-95fe-69b40551af61/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-08 19:37:25","sources":[{"name":"Wordfence","remoteId":"8f66e25f-b67e-4227-95fe-69b40551af61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8f66e25f-b67e-4227-95fe-69b40551af61?source=api-prod","cve":"CVE-2026-12418","affectedVersions":"<=4.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/991327f0-8bb9-4fdf-9c2a-b266ead962a3/wp-user-frontend","title":"WP User Frontend <= 4.1.12 - Authenticated (Subscriber+) Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"991327f0-8bb9-4fdf-9c2a-b266ead962a3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/991327f0-8bb9-4fdf-9c2a-b266ead962a3?source=api-prod","cve":"CVE-2025-58673","affectedVersions":"<=4.1.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/a02d9a01-1104-4935-8074-af4367c66278/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Subscription Overwrite\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-07 23:49:15","sources":[{"name":"Wordfence","remoteId":"a02d9a01-1104-4935-8074-af4367c66278"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a02d9a01-1104-4935-8074-af4367c66278?source=api-prod","cve":"CVE-2026-5459","affectedVersions":"<=4.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/a4cf3ab0-7215-43f2-8ad7-c587d3376c26/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"a4cf3ab0-7215-43f2-8ad7-c587d3376c26"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4cf3ab0-7215-43f2-8ad7-c587d3376c26?source=api-prod","cve":"CVE-2026-32485","affectedVersions":"<=4.2.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/b9793793-44d5-4628-a57b-c1254645e648/wp-user-frontend","title":"WP User Frontend <= 3.5.25 - SQL Injection & Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-12-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"b9793793-44d5-4628-a57b-c1254645e648"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b9793793-44d5-4628-a57b-c1254645e648?source=api-prod","cve":"CVE-2021-25076","affectedVersions":"<=3.5.25","severity":"high"},{"advisoryId":"WPSECADV/WF/d2fdd6eb-c848-446c-abad-7d2ea93f5512/wp-user-frontend","title":"WP User Frontend <= 4.0.7 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"d2fdd6eb-c848-446c-abad-7d2ea93f5512"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d2fdd6eb-c848-446c-abad-7d2ea93f5512?source=api-prod","cve":"CVE-2024-38693","affectedVersions":"<=4.0.7","severity":"critical"},{"advisoryId":"WPSECADV/WF/e0a278a3-f229-4673-8b3e-5b68f383dcc7/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-14 14:13:22","sources":[{"name":"Wordfence","remoteId":"e0a278a3-f229-4673-8b3e-5b68f383dcc7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e0a278a3-f229-4673-8b3e-5b68f383dcc7?source=api-prod","cve":"CVE-2026-2233","affectedVersions":"<=4.2.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/e869800a-6fbc-4a1a-97fd-92ecbf3305ff/wp-user-frontend","title":"Appsero <= 1.2.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"e869800a-6fbc-4a1a-97fd-92ecbf3305ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e869800a-6fbc-4a1a-97fd-92ecbf3305ff?source=api-prod","cve":"CVE-2022-47150","affectedVersions":"<=3.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/eb53282a-2298-4582-92bf-59221089172e/wp-user-frontend","title":"WP User Frontend <= 4.1.12 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"eb53282a-2298-4582-92bf-59221089172e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eb53282a-2298-4582-92bf-59221089172e?source=api-prod","cve":"CVE-2025-58672","affectedVersions":"<=4.1.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/ffdf34bb-a887-444c-8a76-12901fed6662/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.2 - Missing Authorization to Authenticated (Subscriber+) Subscription Pack Cancellation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-06-08 20:48:06","sources":[{"name":"Wordfence","remoteId":"ffdf34bb-a887-444c-8a76-12901fed6662"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ffdf34bb-a887-444c-8a76-12901fed6662?source=api-prod","cve":"CVE-2026-4058","affectedVersions":"<=4.3.2","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0049583a-0ad3-45e4-a29e-4b8c33d09857/wp-user-frontend","title":"User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-08 19:22:00","sources":[{"name":"Wordfence","remoteId":"0049583a-0ad3-45e4-a29e-4b8c33d09857"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0049583a-0ad3-45e4-a29e-4b8c33d09857?source=api-prod","cve":"CVE-2026-12406","affectedVersions":"<=4.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/09e5391d-2671-4bb4-9adc-29b5fdb59240/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"09e5391d-2671-4bb4-9adc-29b5fdb59240"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/09e5391d-2671-4bb4-9adc-29b5fdb59240?source=api-prod","cve":"CVE-2026-24364","affectedVersions":"<=4.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/1e2b99ac-62f4-4180-aabe-91a5c717ea71/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration <= 4.3.7 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-06-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"1e2b99ac-62f4-4180-aabe-91a5c717ea71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1e2b99ac-62f4-4180-aabe-91a5c717ea71?source=api-prod","cve":"CVE-2026-57334","affectedVersions":"<=4.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/233f3415-9d4f-4ddb-af69-55c832ff67a1/wp-user-frontend","title":"User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration < 4.3.8 - Missing Authorization to Unauthenticated Media Attachment Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"233f3415-9d4f-4ddb-af69-55c832ff67a1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/233f3415-9d4f-4ddb-af69-55c832ff67a1?source=api-prod","cve":"CVE-2026-14568","affectedVersions":"<4.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/2b5d27cc-c6eb-4c5c-8ee1-30483b91c6fd/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Authenticated (Subscriber+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-07 19:58:37","sources":[{"name":"Wordfence","remoteId":"2b5d27cc-c6eb-4c5c-8ee1-30483b91c6fd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b5d27cc-c6eb-4c5c-8ee1-30483b91c6fd?source=api-prod","cve":"CVE-2026-5127","affectedVersions":"<=4.3.1","severity":"high"},{"advisoryId":"WPSECADV/WF/2c358cbe-7600-43a1-94a3-1530cdb5a9f3/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Authenticated (Author+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-26 06:37:58","sources":[{"name":"Wordfence","remoteId":"2c358cbe-7600-43a1-94a3-1530cdb5a9f3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2c358cbe-7600-43a1-94a3-1530cdb5a9f3?source=api-prod","cve":"CVE-2026-1565","affectedVersions":"<=4.2.8","severity":"high"},{"advisoryId":"WPSECADV/WF/31de3c9b-068d-47d8-9811-feae07f2e9d0/wp-user-frontend","title":"WP User Frontend <= 3.6.5 - Authenticated (Author+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"31de3c9b-068d-47d8-9811-feae07f2e9d0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/31de3c9b-068d-47d8-9811-feae07f2e9d0?source=api-prod","cve":"CVE-2023-47682","affectedVersions":"<=3.6.5","severity":"high"},{"advisoryId":"WPSECADV/WF/379a5016-3968-4b28-8d6e-0f517e419016/wp-user-frontend","title":"Various Plugins <= Various Version - Use of Polyfill.io\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"379a5016-3968-4b28-8d6e-0f517e419016"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/379a5016-3968-4b28-8d6e-0f517e419016?source=api-prod","affectedVersions":"<=4.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/3c476263-72b7-48f1-8ba3-91d69eae7b6a/wp-user-frontend","title":"WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPress < 3.5.25 - Authenticated (Admin+) SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"3c476263-72b7-48f1-8ba3-91d69eae7b6a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3c476263-72b7-48f1-8ba3-91d69eae7b6a?source=api-prod","affectedVersions":"<3.5.25","severity":"high"},{"advisoryId":"WPSECADV/WF/4a0f77ca-2fb5-4e73-a0fa-dfbeb39fbd84/wp-user-frontend","title":"WP User Frontend <= 3.5.28 - Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"4a0f77ca-2fb5-4e73-a0fa-dfbeb39fbd84"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4a0f77ca-2fb5-4e73-a0fa-dfbeb39fbd84?source=api-prod","cve":"CVE-2021-24649","affectedVersions":"<=3.5.28","severity":"high"},{"advisoryId":"WPSECADV/WF/6844c9a6-b25a-4ae1-96f6-023c1df80ddf/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"6844c9a6-b25a-4ae1-96f6-023c1df80ddf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6844c9a6-b25a-4ae1-96f6-023c1df80ddf?source=api-prod","cve":"CVE-2026-42412","affectedVersions":"<=4.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/6e95b16f-a25a-45c7-a875-2d34a1e127ce/wp-user-frontend","title":"WP User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-01 13:23:01","sources":[{"name":"Wordfence","remoteId":"6e95b16f-a25a-45c7-a875-2d34a1e127ce"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6e95b16f-a25a-45c7-a875-2d34a1e127ce?source=api-prod","cve":"CVE-2025-14047","affectedVersions":"<=4.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/84003388-c47c-41db-8d2d-4643aa375a89/wp-user-frontend","title":"Appsero <= 1.2.1 - Missing Authorization\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"84003388-c47c-41db-8d2d-4643aa375a89"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/84003388-c47c-41db-8d2d-4643aa375a89?source=api-prod","affectedVersions":"<=3.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/8a2186c9-fa27-4d7d-be41-c82711c49334/wp-user-frontend","title":"WP User Frontend < 2.3.11 - Arbitrary File Upload\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-02-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"8a2186c9-fa27-4d7d-be41-c82711c49334"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8a2186c9-fa27-4d7d-be41-c82711c49334?source=api-prod","affectedVersions":"<2.3.11","severity":"critical"},{"advisoryId":"WPSECADV/WF/8e8e967f-f627-4c0c-ac0f-0a66ae25c602/wp-user-frontend","title":"WP User Frontend <= 3.6.8 - Missing Authorization via AJAX actions\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e8e967f-f627-4c0c-ac0f-0a66ae25c602"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e8e967f-f627-4c0c-ac0f-0a66ae25c602?source=api-prod","cve":"CVE-2023-45002","affectedVersions":"<=3.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/8f66e25f-b67e-4227-95fe-69b40551af61/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-08 19:37:25","sources":[{"name":"Wordfence","remoteId":"8f66e25f-b67e-4227-95fe-69b40551af61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8f66e25f-b67e-4227-95fe-69b40551af61?source=api-prod","cve":"CVE-2026-12418","affectedVersions":"<=4.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/991327f0-8bb9-4fdf-9c2a-b266ead962a3/wp-user-frontend","title":"WP User Frontend <= 4.1.12 - Authenticated (Subscriber+) Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"991327f0-8bb9-4fdf-9c2a-b266ead962a3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/991327f0-8bb9-4fdf-9c2a-b266ead962a3?source=api-prod","cve":"CVE-2025-58673","affectedVersions":"<=4.1.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/a02d9a01-1104-4935-8074-af4367c66278/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Subscription Overwrite\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-07 23:49:15","sources":[{"name":"Wordfence","remoteId":"a02d9a01-1104-4935-8074-af4367c66278"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a02d9a01-1104-4935-8074-af4367c66278?source=api-prod","cve":"CVE-2026-5459","affectedVersions":"<=4.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/a4cf3ab0-7215-43f2-8ad7-c587d3376c26/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"a4cf3ab0-7215-43f2-8ad7-c587d3376c26"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4cf3ab0-7215-43f2-8ad7-c587d3376c26?source=api-prod","cve":"CVE-2026-32485","affectedVersions":"<=4.2.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/b9793793-44d5-4628-a57b-c1254645e648/wp-user-frontend","title":"WP User Frontend <= 3.5.25 - SQL Injection & Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-12-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"b9793793-44d5-4628-a57b-c1254645e648"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b9793793-44d5-4628-a57b-c1254645e648?source=api-prod","cve":"CVE-2021-25076","affectedVersions":"<=3.5.25","severity":"high"},{"advisoryId":"WPSECADV/WF/d2fdd6eb-c848-446c-abad-7d2ea93f5512/wp-user-frontend","title":"WP User Frontend <= 4.0.7 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"d2fdd6eb-c848-446c-abad-7d2ea93f5512"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d2fdd6eb-c848-446c-abad-7d2ea93f5512?source=api-prod","cve":"CVE-2024-38693","affectedVersions":"<=4.0.7","severity":"critical"},{"advisoryId":"WPSECADV/WF/e0a278a3-f229-4673-8b3e-5b68f383dcc7/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-14 14:13:22","sources":[{"name":"Wordfence","remoteId":"e0a278a3-f229-4673-8b3e-5b68f383dcc7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e0a278a3-f229-4673-8b3e-5b68f383dcc7?source=api-prod","cve":"CVE-2026-2233","affectedVersions":"<=4.2.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/e869800a-6fbc-4a1a-97fd-92ecbf3305ff/wp-user-frontend","title":"Appsero <= 1.2.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"e869800a-6fbc-4a1a-97fd-92ecbf3305ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e869800a-6fbc-4a1a-97fd-92ecbf3305ff?source=api-prod","cve":"CVE-2022-47150","affectedVersions":"<=3.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/eb53282a-2298-4582-92bf-59221089172e/wp-user-frontend","title":"WP User Frontend <= 4.1.12 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"eb53282a-2298-4582-92bf-59221089172e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eb53282a-2298-4582-92bf-59221089172e?source=api-prod","cve":"CVE-2025-58672","affectedVersions":"<=4.1.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/ffdf34bb-a887-444c-8a76-12901fed6662/wp-user-frontend","title":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.2 - Missing Authorization to Authenticated (Subscriber+) Subscription Pack Cancellation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-06-08 20:48:06","sources":[{"name":"Wordfence","remoteId":"ffdf34bb-a887-444c-8a76-12901fed6662"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ffdf34bb-a887-444c-8a76-12901fed6662?source=api-prod","cve":"CVE-2026-4058","affectedVersions":"<=4.3.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_73747265616d6974811c9dc5_gen.json b/internal/data/assets/theme_73747265616d6974811c9dc5_gen.json index 0e8b997d..fb5d190d 100644 --- a/internal/data/assets/theme_73747265616d6974811c9dc5_gen.json +++ b/internal/data/assets/theme_73747265616d6974811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/057abffb-1c52-49ca-8791-ca44f0c5a011/streamit","title":"Streamit <= 4.0.2 - Authenticated (Subscriber+) Privilege Escalation via User Email Change/Account Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"057abffb-1c52-49ca-8791-ca44f0c5a011"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/057abffb-1c52-49ca-8791-ca44f0c5a011?source=api-prod","cve":"CVE-2025-2526","affectedVersions":"<=4.0.2","severity":"high"},{"advisoryId":"WPSECADV/WF/83a58119-d0ed-47fe-93d1-1aa1def2cf44/streamit","title":"Streamit <= 4.0.1 - Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"83a58119-d0ed-47fe-93d1-1aa1def2cf44"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/83a58119-d0ed-47fe-93d1-1aa1def2cf44?source=api-prod","cve":"CVE-2025-2525","affectedVersions":"<=4.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/fd28c405-ed2f-435a-806c-1fc43cac0f80/streamit","title":"Streamit <= 4.0.1 - Authenticated (Subscriber+) Arbitrary File Download\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd28c405-ed2f-435a-806c-1fc43cac0f80"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd28c405-ed2f-435a-806c-1fc43cac0f80?source=api-prod","cve":"CVE-2025-2519","affectedVersions":"<=4.0.1","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/057abffb-1c52-49ca-8791-ca44f0c5a011/streamit","title":"Streamit <= 4.0.2 - Authenticated (Subscriber+) Privilege Escalation via User Email Change/Account Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"057abffb-1c52-49ca-8791-ca44f0c5a011"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/057abffb-1c52-49ca-8791-ca44f0c5a011?source=api-prod","cve":"CVE-2025-2526","affectedVersions":"<=4.0.2","severity":"high"},{"advisoryId":"WPSECADV/WF/83a58119-d0ed-47fe-93d1-1aa1def2cf44/streamit","title":"Streamit <= 4.0.1 - Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"83a58119-d0ed-47fe-93d1-1aa1def2cf44"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/83a58119-d0ed-47fe-93d1-1aa1def2cf44?source=api-prod","cve":"CVE-2025-2525","affectedVersions":"<=4.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/f5ab09ee-53d2-4d99-824b-6a7a006bb2c2/streamit","title":"Streamit <= 4.5.0 - Unauthenticated Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"f5ab09ee-53d2-4d99-824b-6a7a006bb2c2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f5ab09ee-53d2-4d99-824b-6a7a006bb2c2?source=api-prod","cve":"CVE-2026-13423","affectedVersions":"<=4.5.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/fd28c405-ed2f-435a-806c-1fc43cac0f80/streamit","title":"Streamit <= 4.0.1 - Authenticated (Subscriber+) Arbitrary File Download\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd28c405-ed2f-435a-806c-1fc43cac0f80"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd28c405-ed2f-435a-806c-1fc43cac0f80?source=api-prod","cve":"CVE-2025-2519","affectedVersions":"<=4.0.1","severity":"medium"}] \ No newline at end of file