VYPR
Vendor

Webcraftic

Products
3
CVEs
5
Across products
5
Status
Private

Products

3

Recent CVEs

5
  • CVE-2019-15858HigSep 3, 2019
    risk 0.59cvss 8.8epss 0.18

    admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.

  • CVE-2019-14773HigAug 8, 2019
    risk 0.49cvss 7.5epss 0.02

    admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion.

  • CVE-2019-15818MedAug 30, 2019
    risk 0.40cvss 6.1epss 0.01

    The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.

  • CVE-2019-15776MedAug 29, 2019
    risk 0.40cvss 6.1epss 0.01

    The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.

  • CVE-2019-16289MedSep 13, 2019
    risk 0.35cvss 5.4epss 0.01

    The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.