Aggregates CVE and security vulnerability intelligence across all infolific-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk csrf and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-50873 | Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Add Any Extension to Pages.This issue affects Add Any Extension to Pages: from n/a through 1.4. | [email protected] | 4.3 | 0.23% | 2023-12-28 | 2026-04-28 |
| CVE-2023-28618 | Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Enhanced Plugin Admin plugin <= 1.16 versions. | [email protected] | 5.4 | 0.31% | 2023-11-12 | 2024-11-21 |
| CVE-2020-35135 | The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF. | [email protected] | 8.8 | 0.89% | 2020-12-11 | 2024-11-21 |
| CVE-2020-13641 | An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with malicious JavaScript, allowing for that be executed later in the victims browser. | [email protected] | 8.8 | 0.81% | 2020-05-28 | 2024-11-21 |