Advancedplugins develops the Ultimate Image Tool, a WordPress plugin focused on image management and manipulation, where the observed vulnerability pattern centers on access-control and path-traversal issues. These weakness classes reflect risks common to file-handling and permission-management contexts in web application plugins; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Advancedplugins over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-28390CRITICAL An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sensitive information via Improper | Mar 14, 2024 | 9.8 | 25 | NO | NO |
CVE-2023-30200HIGH In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Advanced Plugins for PrestaShop, a guest can download personal | Jul 20, 2023 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Advancedplugins.
Media articles that mention a CVE ID that affects a product developed by Advancedplugins — matched by CVE ID, not by vendor name.