Catchsquare's vulnerability footprint concentrates in WordPress plugins, specifically its social widget and smart preloader components, which present a narrow but potentially high-reach attack surface given WordPress's ubiquity. The observed weakness class recurs around improper input neutralization during web page generation, a characteristic flaw pattern in plugin-level content handling where output is not properly escaped before rendering in user browsers. Current vulnerability counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Catchsquare over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-57981MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget wp-social-widget allows Stored XSS.This issue aff | Sep 22, 2025 | 5.4 | 19 | NO | NO |
CVE-2023-23675MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catchsquare WP Smart Preloader plugin <= 1.15 versions. | Mar 30, 2023 | 4.8 | 19 | NO | NO |
CVE-2023-0074MEDIUM The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is e | Jan 30, 2023 | 5.4 | 19 | NO | NO |
CVE-2025-30610MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget wp-social-widget allows Stored XSS.This issue aff | Mar 24, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-27189MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget allows Stored XSS.This issue affects WP Social Wi | Mar 15, 2024 | 5.4 | 17 | NO | NO |
CVE-2025-49306MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget wp-social-widget allows Stored XSS.This issue aff | Jun 6, 2025 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Catchsquare.
Media articles that mention a CVE ID that affects a product developed by Catchsquare — matched by CVE ID, not by vendor name.