Vulnerabilities > Plechevandrey

DATE CVE VULNERABILITY TITLE RISK
2024-09-06 CVE-2024-8292 Authorization Bypass Through User-Controlled Key vulnerability in Plechevandrey Wp-Recall
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8.
network
low complexity
plechevandrey CWE-639
critical
9.8
2024-06-06 CVE-2024-1175 Missing Authorization vulnerability in Plechevandrey Wp-Recall
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_payment' function in all versions up to, and including, 16.26.6.
network
low complexity
plechevandrey CWE-862
5.3