Acurax develops a modest portfolio of web-based widgets and overlay components focused on social-media integration and site-maintenance functionality, representing a narrow but strategically placed footprint in client-side web applications. Its disclosed vulnerabilities cluster around input-handling and session-management weaknesses, including cross-site scripting, cross-site request forgery, authentication bypass, and information exposure, which are characteristic of web-facing components that handle user interaction and credential state. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Acurax over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6357HIGH The acx_asmw_saveorder_callback function in function.php in the acurax-social-media-widget plugin before 3.2.6 for WordPress has CSRF via the recordsArray parameter to wp-admin/adm | Jan 27, 2018 | 8.8 | 27 | NO | NO |
CVE-2023-6922MEDIUM The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.6 via the 'acx_csma_s | Feb 28, 2024 | 6.5 | 18 | NO | NO |
CVE-2023-39926MEDIUM Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Acurax Under Construction / Maintenance Mode from Acurax plugin <= 2.6 versions. | Nov 16, 2023 | 6.1 | 18 | NO | NO |
CVE-2021-36843MEDIUM Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Floating Social Media Icon plugin (versions <= 4.3.5) Social Media Configuration form. Require | Nov 26, 2021 | 4.8 | 18 | NO | NO |
CVE-2024-35749MEDIUM Authentication Bypass by Spoofing vulnerability in Acurax Under Construction / Maintenance Mode from Acurax allows Authentication Bypass.This issue affects Under Construction / Mai | Jun 10, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-1476MEDIUM The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6 via the REST AP | Feb 28, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Acurax.
Media articles that mention a CVE ID that affects a product developed by Acurax — matched by CVE ID, not by vendor name.