Accessally develops a focused suite of web-based marketing and access-control plugins, including PopupAlly and Accessally, that serve small-to-medium business automation and membership workflows. The durable signal centers on web-application input handling and authorization logic, with recurring exposure in cross-site scripting, sensitive information disclosure, and missing authorization controls characteristic of plugin-based platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Accessally over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24226HIGH In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping seriali | Apr 12, 2021 | 7.5 | 33 | NO | YES |
CVE-2024-34796MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: fr | Jun 3, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-33639MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a | Apr 26, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-23520MEDIUM Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0. | Mar 26, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Accessally.
Media articles that mention a CVE ID that affects a product developed by Accessally — matched by CVE ID, not by vendor name.