A3rev develops a portfolio of WordPress plugins and themes focused on e-commerce and portfolio functionality, including products such as Page View Count, Contact Us pages, and A3 Portfolio that serve a broadly distributed user base. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the recurring exposure centers on web-application input-handling and authorization weaknesses including cross-site scripting, SQL injection, cross-site request forgery, and missing authorization controls that are typical of WordPress plugin ecosystems where validation boundaries can be permeable. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by A3rev over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0434CRITICAL The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both una | Mar 7, 2022 | 9.8 | 41 | NO | YES |
CVE-2025-2816HIGH The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the yellow_mes | May 1, 2025 | 8.1 | 22 | NO | NO |
CVE-2023-23973MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Contact Us Page – Contact People plugin <= 3.7.0. | Mar 1, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-0095MEDIUM The Page View Count WordPress plugin before 2.6.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which | Feb 6, 2023 | 5.4 | 19 | NO | NO |
CVE-2021-24509MEDIUM The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing users with a role as low as Contributor to perform Stored XS | Aug 9, 2021 | 5.4 | 19 | NO | NO |
CVE-2022-40131MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Page View Count plugin <= 2.5.5 on WordPress allows an attacker to reset the plugin settings. | Nov 3, 2022 | 4.3 | 18 | NO | NO |
CVE-2025-5123MEDIUM The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 3.7.4 due to | Jun 13, 2025 | 5.4 | 17 | NO | NO |
CVE-2023-29097MEDIUM Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in a3rev Software a3 Portfolio plugin <= 3.1.0 versions. | Aug 14, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by A3rev.
Media articles that mention a CVE ID that affects a product developed by A3rev — matched by CVE ID, not by vendor name.