Pricing
WordPress securityInstantly fix and mitigate vulnerabilitiesPlugin auditingPaid auditing for WordPress vendorsManaged VDPStart a security program for your pluginsBug BountyJoin the community and earn bountiesEnterprise APIAt scale monitoring and vPatching for hostsVulnerability databaseThe latest WordPress security intelligence
Login Start trial

Hiro (Code016Hiro)

195.85

XP

18

Reports

0

Reports, last 90 days

#19

18 Nov, 2025
Lvl 1
0
0
0
0
Website
X
GitHub
Affected software | Vulnerability
CVE
AXP
Severity
Reported
Frontend File Manager<= 23.3
Broken Access Control
10.6
5.3
Jul 11, 2025
Ninja Charts<= 3.3.5
Sensitive Data Exposure
10.6
5.3
Jun 10, 2025
Surfer<= 1.6.4.574
Broken Access Control
10.6
5.3
Jul 27, 2025
Create by Mediavine<= 1.10.1
Insecure Direct Object References (IDOR)
31.8
5.3
No date
Custom API for WP<= 4.2.2
Privilege Escalation
29.7
9.9
Jun 8, 2025
Custom API for WP<= 4.2.2
SQL Injection
37.2
9.3
Jun 8, 2025
Webba Booking<= 5.1.20
Broken Access Control
14.95
6.5
Jun 15, 2025
Trusty Whistleblowing<= 1.5.2
Broken Access Control
12.3
8.2
May 8, 2025
App Builder<= 5.5.4
Broken Access Control
10.6
5.3
May 15, 2025
WP Employee Attendance System<= 3.5
SQL Injection
N/A
7.6
Apr 25, 2025
Elastic Email Subscribe Form<= 1.2.2
Broken Access Control
N/A
5.4
May 5, 2025
WP AutoKeyword<= 1.0
Broken Access Control
N/A
5.3
Apr 25, 2025
HR Management Lite<= 3.4
Cross Site Request Forgery (CSRF)
2.15
4.3
Apr 22, 2025
Taskbuilder<= 4.0.7
Broken Access Control
7.95
5.3
May 2, 2025
Newspack Newsletters<= 3.13.0
Open Redirection
9.4
4.7
May 19, 2025
Job Board Manager<= 2.1.60
Broken Access Control
7.95
5.3
May 9, 2025
Verge3D<= 4.9.3
Cross Site Scripting (XSS)
10.65
7.1
May 7, 2025
WP HRM LITE<= 1.1
SQL Injection
N/A
9.3
Apr 17, 2025

Report vulnerabilities to earn bounties and rewards!

Read more

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • Documentation
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Vulnerability database
  • Whitepaper 2025 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
© 2025 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions
EU Flag