Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Addonmaster

First CVE: Nov 30, 2023Active for: 3 yearsTotal CVEs: 9

Addonmaster's vulnerability footprint centers on a compact set of WordPress plugins, including Post Grid Master, Bootstrap Shortcodes Ultimate, and Load More Anything, that extend site functionality across a significant installed base. Vulnerabilities affecting these plugins skew toward serious outcomes and recur through weakness classes including cross-site scripting, missing authorization controls, PHP remote file inclusion, and path traversal—patterns characteristic of plugin-layer input handling and file-access logic. Defenders should apply patches to affected WordPress installations systematically, as the plugins' broad adoption amplifies the risk exposure; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Addonmaster over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 30, 2023
2 years ago
Most Recent CVE
Jul 24, 2025
365 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-11642CRITICAL
The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to
Jan 9, 20259.827NONO
CVE-2025-30974HIGH
Missing Authorization vulnerability in Akhtarujjaman Shuvo Post Grid Master ajax-filter-posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff
Jun 6, 20258.823NONO
CVE-2025-5084MEDIUM
The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘argsArray['read_more_text']’ parameter in all versions up to, and including, 3.4.
Jul 24, 20256.122NONO
CVE-2025-24733MEDIUM
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Akhtarujjaman Shuvo Post Grid Master ajax-filter-posts allo
Jan 24, 20256.522NONO
CVE-2024-43156MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AddonMaster Post Grid Master allows Reflected XSS.This issue affects Po
Aug 12, 20246.119NONO
CVE-2024-24704MEDIUM
Missing Authorization vulnerability in AddonMaster Load More Anything.This issue affects Load More Anything: from n/a through 3.3.3.
Jun 11, 20246.318NONO
CVE-2024-34390MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonMaster Post Grid Master allows Stored XSS.This issue affects Post Grid Ma
May 6, 20246.518NONO
CVE-2023-47851MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akhtarujjaman Shuvo Bootstrap Shortcodes Ultimate allows Stored XSS.This issue
Nov 30, 20235.417NONO
CVE-2024-34372MEDIUM
Missing Authorization vulnerability in AddonMaster Post Grid Master.This issue affects Post Grid Master: from n/a through 3.4.7.
May 6, 20245.316NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
78%
11%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (55.6%)
Unknown0 (0.0%)
Required4 (44.4%)
Privileges Required
Low5 (55.6%)
High0 (0.0%)
None4 (44.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Addonmaster.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Addonmaster — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Addonmaster's Products

View all 2 CNAs →

Top CWEs