Ari Soft develops a focused line of WordPress-oriented plugins and extensions, including quiz functionality, database management, form connectors, and lightbox utilities that serve a niche but engaged user base. The vendor's vulnerability disclosures span this specialized plugin portfolio without concentrating on a single dominant weakness class; defenders tracking WordPress ecosystem security should include these components in their inventory monitoring. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ari Soft over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-52182HIGH Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a thr | Dec 31, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-51487HIGH Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft ARI Stream Quiz.This issue affects ARI Stream Quiz: from n/a through 1.2.32. | Mar 16, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-24884HIGH Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft Contact Form 7 Connector.This issue affects Contact Form 7 Connector: from n/a through 1.2.2. | Feb 12, 2024 | 8.8 | 24 | NO | NO |
CVE-2019-25215HIGH The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin in versions up to, and including | Oct 16, 2024 | 7.3 | 23 | NO | NO |
CVE-2022-0161MEDIUM The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Sc | Mar 14, 2022 | 6.1 | 21 | NO | NO |
CVE-2020-19156MEDIUM Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' fu | Sep 15, 2021 | 5.4 | 20 | NO | NO |
CVE-2023-47513MEDIUM Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in ARI Soft ARI Stream Quiz allows Code Injection.This issue affects ARI Stream Quiz: fr | Jun 4, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-0239MEDIUM The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripti | Jan 16, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-47835MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder plugin <= 1.2.32 versions | Nov 23, 2023 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ari Soft.
Media articles that mention a CVE ID that affects a product developed by Ari Soft — matched by CVE ID, not by vendor name.