← All credits
AmrAwad
30 vulnerability records and advisories credit this contributor.
CVE-2024-7135
Tainacan <= 0.21.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read
CVE-2024-6500
InPost for WooCommerce <= 1.4.0 and InPost PL <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary File Read and Delete
CVE-2024-6353
Wallet for WooCommerce <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'search[value]'
CVE-2024-5654
CF7 Google Sheets Connector <= 5.0.9 - Missing Authorization to Limited Site Configuration Update
CVE-2024-5326
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update
CVE-2024-5324
XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update
CVE-2024-4875
HT Mega – Absolute Addons For Elementor <= 2.5.2 - Missing Authorization to Options Update
CVE-2024-4444
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration
CVE-2024-4434
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection
CVE-2024-4319
Advanced Contact form 7 DB <= 2.0.2 - Missing Authorization to Unauthenticated Information Disclosure