Zanematthew's vulnerability profile centers on its ZM Ajax Login & Register plugin, a web-facing authentication component where observed weaknesses cluster around path-traversal and cross-site scripting flaws typical of input-handling issues in access-control plugins. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zanematthew over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-4153MEDIUM Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arbitrary php files via a relativ | Jun 10, 2015 | 5.0 | 32 | NO | YES |
CVE-2023-2027CRITICAL The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the us | Apr 15, 2023 | 9.8 | 29 | NO | NO |
CVE-2015-4465MEDIUM Cross-site scripting (XSS) vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspec | Jun 10, 2015 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zanematthew.
Media articles that mention a CVE ID that affects a product developed by Zanematthew — matched by CVE ID, not by vendor name.