Cagewebdev develops a focused collection of WordPress plugins including Order Your Posts Manually, Float to Top Button, and Optimize Database After Deleting Revisions, where vulnerability exposure clusters around web application input-handling weaknesses. The recurring weakness classes—cross-site scripting, cross-site request forgery, and SQL injection—reflect the attack surface inherent to WordPress plugin development and server-side form processing. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cagewebdev over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25980HIGH Cross-Site Request Forgery (CSRF) vulnerability in CAGE Web Design | Rolf van Gelder Optimize Database after Deleting Revisions plugin <= 5.1 versions. | Oct 4, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-32508HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolf van Gelder Order Your Posts Manually allows SQL Injection.This issue affe | Nov 3, 2023 | 7.2 | 21 | NO | NO |
CVE-2022-2709MEDIUM The Float to Top Button WordPress plugin through 2.3.6 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scrip | Sep 19, 2022 | 4.8 | 19 | NO | NO |
CVE-2023-32510MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <= 2.2.5 versions. | Aug 24, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-32509MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <= 2.2.5 versions. | Aug 23, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cagewebdev.
Media articles that mention a CVE ID that affects a product developed by Cagewebdev — matched by CVE ID, not by vendor name.