VYPR
Vendor

Riverforest Wp

Products
3
CVEs
4
Across products
4
Status
Private

Products

3

Recent CVEs

4
  • CVE-2023-4019HigSep 4, 2023
    risk 0.57cvss 8.8epss 0.01

    The Media from FTP WordPress plugin before 11.17 does not properly limit who can use the plugin, which may allow users with author+ privileges to move files around, like wp-config.php, which may lead to RCE in some cases.

  • CVE-2023-4035MedAug 30, 2023
    risk 0.35cvss 5.4epss 0.00

    The Simple Blog Card WordPress plugin before 1.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site…

  • CVE-2023-4036MedAug 30, 2023
    risk 0.28cvss 4.3epss 0.00

    The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones

  • CVE-2023-4023MedAug 30, 2023
    risk 0.28cvss 4.3epss 0.00

    The All Users Messenger WordPress plugin through 1.24 does not prevent non-administrator users from deleting messages from the all-users messenger.