Author: Angelo Barbosa

CVE-2024-13721 | plethoraplugins Plethora Plugins Tabs and Accordions Plugin up to 1.1.8 on WordPress anchor cross site scripting

A vulnerability, which was classified as critical, has been found in plethoraplugins Plethora Plugins Tabs and Accordions Plugin up to 1.1.8 on WordPress. Affected by this issue is some unknown functionality. The manipulation of the argument anchor leads to doubled character xss manipulations. This vulnerability is handled as CVE-2024-13721. The attack may be launched remotely. There is no exploit...

Read More

CVE-2025-0682 | ThemeREX Addons Plugin up to 2.33.0 on WordPress Shortcode trx_sc_reviews type filename control

A vulnerability classified as critical was found in ThemeREX Addons Plugin up to 2.33.0 on WordPress. Affected by this vulnerability is the function trx_sc_reviews of the component Shortcode Handler. The manipulation of the argument type leads to improper control of filename for include/require statement in php program (‘php remote file inclusion’). This vulnerability is known as CVE-2025-0682. The attack can be launched remotely. There is no exploit...

Read More

CVE-2024-50695 | SunGrow WiNet up to 200.001.00.P027 MQTT Message stack-based overflow

A vulnerability classified as critical has been found in SunGrow WiNet up to 200.001.00.P027. Affected is an unknown function of the component MQTT Message Handler. The manipulation leads to stack-based buffer overflow. This vulnerability is traded as CVE-2024-50695. Access to the local network is required for this attack to succeed. There is no exploit...

Read More

CVE-2024-50697 | SunGrow WiNet up to 200.001.00.P027 MQTT Message stack-based overflow

A vulnerability was found in SunGrow WiNet up to 200.001.00.P027. It has been rated as critical. This issue affects some unknown processing of the component MQTT Message Handler. The manipulation leads to stack-based buffer overflow. The identification of this vulnerability is CVE-2024-50697. Access to the local network is required for this attack. There is no exploit...

Read More

CVE-2024-50690 | SunGrow WiNet up to 200.001.00.P027 Firmware Update hard-coded password

A vulnerability was found in SunGrow WiNet up to 200.001.00.P027. It has been declared as problematic. This vulnerability affects unknown code of the component Firmware Update Handler. The manipulation leads to use of hard-coded password. This vulnerability was named CVE-2024-50690. The attack needs to be initiated within the local network. There is no exploit...

Read More