Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

realmag777 — Vulnerabilities & Security Advisories 122

Browse all 122 CVE security advisories affecting realmag777. AI-powered Chinese analysis, POCs, and references for each vulnerability.

realmag777 is a software vendor primarily known for developing and distributing e-commerce solutions and digital marketplace platforms. Historical security audits reveal a pattern of critical vulnerabilities, with 109 CVEs currently on record. The most prevalent flaw classes include Remote Code Execution (RCE) and Cross-Site Scripting (XSS), often stemming from insufficient input validation and improper sanitization of user-supplied data. Additionally, the software has frequently exhibited insecure direct object references and privilege escalation issues, allowing unauthorized users to access sensitive administrative functions or modify system configurations. These defects typically arise from legacy codebases that lack modern security controls and regular patching cycles. Major incidents have involved data breaches exposing customer personal information and payment details due to unpatched SQL injection flaws. The high volume of disclosed vulnerabilities suggests a reactive rather than proactive security posture, requiring immediate attention to code review processes and dependency management to mitigate ongoing risks for enterprise clients relying on this infrastructure.

CVE ID Title CVSS Severity Published
CVE-2024-0790 WOLF – WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Cross-Site Request Forgery — WOLF – WordPress Posts Bulk Editor and Manager Professional CWE-352 5.4 Medium 2024-02-05
CVE-2024-0796 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store <= 1.0.6.1 - Cross-Site Request Forgery — Active Products Tables for WooCommerce. Use constructor to create tables CWE-352 4.3 Medium 2024-02-05
CVE-2024-0791 WOLF – WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Missing Authorization — WOLF – WordPress Posts Bulk Editor and Manager Professional CWE-862 4.3 Medium 2024-02-05
CVE-2024-0797 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store <= 1.0.6.1 - Missing Authorization — Active Products Tables for WooCommerce. Use constructor to create tables CWE-862 4.3 Medium 2024-02-05
CVE-2023-51506 WordPress WPCS Plugin <= 1.2.0 is vulnerable to Cross Site Scripting (XSS) — WPCS – WordPress Currency Switcher Professional CWE-79 5.5 Medium 2024-02-01
CVE-2024-22159 WordPress WOLF Plugin <= 1.0.8 is vulnerable to Cross Site Scripting (XSS) — WOLF – WordPress Posts Bulk Editor and Manager Professional CWE-79 7.1 High 2024-01-31
CVE-2023-6556 FOX – Currency Switcher Professional for WooCommerce <= 1.4.1.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting — FOX – Currency Switcher Professional for WooCommerce CWE-79 5.4 Medium 2024-01-11
CVE-2023-51505 WordPress Active Products Tables for WooCommerce Plugin <= 1.0.6 is vulnerable to PHP Object Injection — Active Products Tables for WooCommerce. Professional products tables for WooCommerce store CWE-502 10.0 Critical 2023-12-29
CVE-2023-40010 WordPress HUSKY – Products Filter for WooCommerce (formerly WOOF) Plugin <= 1.3.4.2 is vulnerable to SQL Injection — HUSKY – Products Filter for WooCommerce Professional CWE-89 9.3 Critical 2023-12-20
CVE-2023-49834 WordPress WOOCS – WooCommerce Currency Switcher Plugin <= 1.4.1.4 is vulnerable to Cross Site Request Forgery (CSRF) — FOX – Currency Switcher Professional for WooCommerce CWE-352 5.4 Medium 2023-12-17
CVE-2023-46152 WordPress WOLF Plugin <= 1.0.7.1 is vulnerable to Cross Site Request Forgery (CSRF) — WOLF – WordPress Posts Bulk Editor and Manager Professional CWE-352 4.3 Medium 2023-10-24
CVE-2023-4941 BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net CWE-862 4.3 Medium 2023-10-20
CVE-2023-4926 BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Deletion — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net CWE-352 5.4 Medium 2023-10-20
CVE-2023-4924 BEAR <= 1.1.3.3 - Missing Authorization to Product Deletion — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net CWE-352 5.4 Medium 2023-10-20
CVE-2023-4923 BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Deletion — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net CWE-352 5.4 Medium 2023-10-20
CVE-2023-4935 BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Profile Creation — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net CWE-352 4.3 Medium 2023-10-20
CVE-2023-4920 BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net CWE-352 4.3 Medium 2023-10-20
CVE-2023-4937 BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Manipulation — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net CWE-352 4.3 Medium 2023-10-20
CVE-2023-4940 BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Manipulation — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net CWE-352 4.3 Medium 2023-10-20
CVE-2023-4943 BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net CWE-862 4.3 Medium 2023-10-20
CVE-2023-4942 BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Manipulation — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net CWE-352 4.3 Medium 2023-10-20
CVE-2023-4938 BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net CWE-862 4.3 Medium 2023-10-18
CVE-2023-44990 WordPress WOLF Plugin <= 1.0.7.1 is vulnerable to Cross Site Scripting (XSS) — WOLF – WordPress Posts Bulk Editor and Manager Professional CWE-79 5.9 Medium 2023-10-17
CVE-2023-31218 WordPress WOLF Plugin <= 1.0.6 is vulnerable to CSRF leading to Stored Cross Site Scripting (XSS) vulnerability — WOLF – WordPress Posts Bulk Editor and Manager Professional CWE-352 7.1 High 2023-08-18
CVE-2023-34028 WordPress WOLF Plugin <= 1.0.7 is vulnerable to Cross Site Request Forgery (CSRF) — WOLF – WordPress Posts Bulk Editor and Manager Professional CWE-352 4.3 Medium 2023-06-22
CVE-2023-2555 WPCS – WordPress Currency Switcher Professional <= 1.1.9 - Missing Authorization to Custom Drop-Down Currency Switcher Creation — WPCS – WordPress Currency Switcher Professional CWE-862 4.3 Medium 2023-06-09
CVE-2023-2557 WPCS – WordPress Currency Switcher Professional <= 1.1.9 - Missing Authorization to Arbitrary Custom Drop-Down Currency Switcher Editing — WPCS – WordPress Currency Switcher Professional CWE-862 4.3 Medium 2023-06-09
CVE-2023-2558 WPCS – WordPress Currency Switcher Professional <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — WPCS – WordPress Currency Switcher Professional CWE-79 6.4 Medium 2023-06-09
CVE-2023-2556 WPCS – WordPress Currency Switcher Professional <= 1.1.9 - Missing Authorization to Arbitrary Custom Drop-Down Currency Switcher Deletion — WPCS – WordPress Currency Switcher Professional CWE-862 4.3 Medium 2023-06-09
CVE-2023-33314 WordPress BEAR Plugin <= 1.1.3.1 is vulnerable to Cross Site Request Forgery (CSRF) — BEAR CWE-352 5.4 Medium 2023-05-28

This page lists every published CVE security advisory associated with realmag777. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.