Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

princeahmed — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting princeahmed. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Princeahmed primarily develops web applications and APIs, focusing on e-commerce and content management systems. Historically, their code has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and insecure authentication mechanisms. While no major public security incidents have been documented, the consistent pattern of vulnerabilities across multiple CVEs suggests systemic weaknesses in secure coding practices. Their products typically require immediate patching due to the severity of identified flaws, with many issues allowing complete system compromise when exploited.

CVE ID Title CVSS Severity Published
CVE-2026-24548 WordPress Radio Player plugin <= 2.0.91 - Server Side Request Forgery (SSRF) vulnerability — Radio Player CWE-918 5.4 Medium 2026-01-23
CVE-2026-24540 WordPress Integrate Google Drive plugin <= 1.5.6 - Broken Access Control vulnerability — Integrate Google Drive CWE-862 5.4 Medium 2026-01-23
CVE-2025-12139 File Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposure — File Manager for Google Drive – Integrate Google Drive CWE-200 7.5 High 2025-11-05
CVE-2025-54703 WordPress Integrate Google Drive plugin <= 1.5.2 - Cross Site Request Forgery (CSRF) vulnerability — Integrate Google Drive CWE-352 4.3 Medium 2025-08-14
CVE-2024-54385 WordPress Radio Player plugin <= 2.0.83 - Server Side Request Forgery (SSRF) vulnerability — Radio Player CWE-918 7.2 High 2024-12-16
CVE-2024-8267 Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress <= 2.0.78 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute — Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player CWE-79 6.4 Medium 2024-09-24
CVE-2023-4025 Radio Player <= 2.0.73 - Missing Authorization to Player Update — Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player CWE-862 5.3 Medium 2024-08-17
CVE-2023-4024 Radio Player <= 2.0.73 - Missing Authorization to Player Deletion — Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player CWE-862 5.3 Medium 2024-08-17
CVE-2023-4027 Radio Player <= 2.0.73 - Missing Authorization to Settings Update — Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player CWE-862 5.3 Medium 2024-08-17
CVE-2024-1042 WP Radio – Worldwide Online Radio Stations Directory for WordPress <= 3.1.9 - Missing Authorization via multiple AJAX actions — WP Radio – Worldwide Online Radio Stations Directory for WordPress CWE-862 6.4 Medium 2024-04-10
CVE-2024-1041 WP Radio – Worldwide Online Radio Stations Directory for WordPress <= 3.1.9 - Authenticated(Subscriber+) Stored Cross-Site Scripting via Settings — WP Radio – Worldwide Online Radio Stations Directory for WordPress CWE-862 6.4 Medium 2024-04-10
CVE-2024-2086 Integrate Google Drive <= 1.3.8 - Missing Authorization to Unauthenticated Settings Modification and Export — File Manager for Google Drive – Integrate Google Drive CWE-862 10.0 Critical 2024-03-30

This page lists every published CVE security advisory associated with princeahmed. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.