Amitzy's vulnerability profile centers on a small portfolio of WordPress plugins—notably Molongui and Molongui Authorship—that handle author metadata and content attribution on publishing sites. The durable signal is concentrated in application-layer input handling and information-disclosure weaknesses, including cross-site scripting, exposure of private personal information, and resource-exposure issues typical of web-facing plugins with access to user and post data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Amitzy over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7014HIGH The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7 | Feb 5, 2024 | 7.5 | 24 | NO | NO |
CVE-2023-39164MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Molongui Author Box for Authors, Co-Authors, Multiple Authors and Guest Authors – Molongui plugin <= 4.6.19 versions. | Sep 4, 2023 | 6.1 | 17 | NO | NO |
CVE-2023-39921MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molongui Author Box, Guest Author and Co-Authors for Your Posts – Molongui all | Nov 30, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Amitzy.
Media articles that mention a CVE ID that affects a product developed by Amitzy — matched by CVE ID, not by vendor name.