← All credits
Rafie Muhammad | Patchstack Bug Bounty Program
214 vulnerability records and advisories credit this contributor.
CVE-2024-43242
WordPress Indeed Ultimate Membership Pro plugin <= 12.7 - Unauthenticated PHP Object Injection vulnerability
CVE-2024-43241
WordPress Indeed Ultimate Membership Pro plugin <= 12.7 - Reflected Cross Site Scripting (XSS) vulnerability
CVE-2024-43240
WordPress Indeed Ultimate Membership Pro plugin <= 12.7 - Unauthenticated Privilege Escalation vulnerability
CVE-2024-43234
WordPress Woffice theme <= 5.4.14 - Unauthenticated Account Takeover vulnerability
CVE-2024-43153
WordPress Woffice theme <= 5.4.10 - Unauthenticated Privilege Escalation vulnerability
CVE-2024-43118
WordPress Hummingbird plugin <= 3.9.1 - Broken Access Control vulnerability
CVE-2024-43117
WordPress Hummingbird plugin <= 3.9.1 - Cross Site Request Forgery (CSRF) vulnerability
CVE-2024-39624
WordPress ListingPro theme <= 2.9.4 - Local File Inclusion vulnerability
CVE-2024-39623
WordPress ListingPro theme <= 2.9.4 - Cross Site Request Forgery (CSRF) to Account Takeover vulnerability
CVE-2024-39622
WordPress ListingPro theme <= 2.9.4 - Unauthenticated SQL Injection vulnerability