Vivektamrakar's vulnerability profile centers on a WordPress REST API plugin, with a narrow but recurring exposure around authentication and file-upload handling. The durable signal reflects application-layer security weaknesses including authentication bypass, missing authentication checks on critical functions, and unsafe file uploads that commonly arise in WordPress plugin development. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vivektamrakar over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-49328CRITICAL Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.This issue affects WP REST API FN | Oct 20, 2024 | 9.8 | 31 | NO | NO |
CVE-2024-49329CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Upload a Web Shell to a Web Server.This issue affects WP REST AP | Oct 20, 2024 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vivektamrakar.
Media articles that mention a CVE ID that affects a product developed by Vivektamrakar — matched by CVE ID, not by vendor name.