VYPR
Vendor

De Baat

Products
2
CVEs
3
Across products
3
Status
Private

Products

2

Recent CVEs

3
  • CVE-2021-24289HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.

  • CVE-2021-24290MedMay 17, 2021
    risk 0.40cvss 6.1epss 0.01

    There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages.

  • CVE-2025-0865MedFeb 19, 2025
    risk 0.35cvss 6.5epss 0.00

    The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3.3. This is due to missing or incorrect nonce validation on the wp_mcm_handle_action_settings() function. This makes it possible for unauthenticated attackers…