Plechevandrey
Plechevandrey Wp-recall: vulnerabilidades y CVE
Plechevandrey Wp-recall tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-52796 | Alta (7.1) | 0.20% | — | 4 jul 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tggfref WP-Recall allows Reflected XSS. This issue affects WP-Recall: from n/a through 16.26.14. |
| CVE-2025-49991 | Media (5.3) | 0.38% | — | 20 jun 2025 | Missing Authorization vulnerability in tggfref WP-Recall allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP-Recall: from n/a through 16.26.14. |
| CVE-2025-30981 | Media (6.3) | 0.15% | — | 6 jun 2025 | Cross-Site Request Forgery (CSRF) vulnerability in tggfref WP-Recall allows Privilege Escalation. This issue affects WP-Recall: from n/a through 16.26.14. |
| CVE-2025-47653 | Alta (7.5) | 0.60% | — | 7 may 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in tggfref WP-Recall allows PHP Local File Inclusion. This issue affects WP-Recall: from n/a through… |
| CVE-2024-9771 | Baja (3.5) | 0.27% | — | 28 abr 2025 | The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2024-9770 | Media (4.7) | 0.32% | — | 25 mar 2025 | The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks |
| CVE-2025-1325 | Media (6.3) | 0.34% | — | 8 mar 2025 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execution due to a missing capability check on the 'rcl_preview_post' AJAX endpoint in all versions up to,… |
| CVE-2025-1324 | Media (5.4) | 0.25% | — | 8 mar 2025 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'public-form' shortcode in all versions up to, and including, 16.26.10 due to… |
| CVE-2025-1323 | Crítica (9.8) | 2.9% | — | 8 mar 2025 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26.10 due to insufficient escaping on the… |
| CVE-2025-1322 | Media (4.3) | 0.46% | — | 8 mar 2025 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 16.26.10 via the 'feed' shortcode due to insufficient restrictions… |
| CVE-2024-8292 | Crítica (9.8) | 0.60% | — | 6 sept 2024 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plugin not properly… |
| CVE-2024-35657 | Media (5.4) | 0.18% | — | 8 jun 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.6. |
| CVE-2024-1175 | Media (5.3) | 0.39% | — | 6 jun 2024 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_payment' function in all versions up to, and… |
| CVE-2024-32710 | Alta (8.5) | 0.60% | — | 24 abr 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5. |
| CVE-2024-32709 | Crítica (9.3) | 5.8% | — | 24 abr 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5. |
| CVE-2024-32604 | Media (4.3) | 0.36% | — | 18 abr 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.