Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pedro Pinho

#19117of 53,632
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-44207
8.6
2026-05-28
WordPress · Eupago Eupago Gateway For Woocommerce · CVE-2026-7862
**Name of the Vulnerable Software and Affected Versions** Eupago Gateway For Woocommerce WordPress plugin versions prior to 4.7.2 **Description** The plugin fails to properly restrict access to its refund request handler. This allows unauthenticated attackers to initiate refunds for any WooCommerce order using the merchant's payment gateway credentials. For certain payment methods, this can be used to redirect the refunded funds to a bank account controlled by the attacker. **Recommendations** Update to version 4.7.2 or later.
PT-2024-21095
5.4
2024-04-04
Esri · Portal For Arcgis · CVE-2024-25697
**Name of the Vulnerable Software and Affected Versions** Portal for ArcGIS versions <=11.1 **Description** The issue is related to a Cross-site Scripting vulnerability that may allow a remote, authenticated attacker to create a crafted link. When an authenticated user opens their bio page, it will render an image in the victim's browser. The privileges required to execute this attack are low. **Recommendations** For Portal for ArcGIS versions <=11.1, update to a version greater than 11.1 to resolve the issue. As a temporary workaround, consider restricting access to bio pages for authenticated users until a patch is available.