Chimpgroup develops a portfolio of web-based business applications spanning job recruitment, food service management, and related sectors, presenting a focused but prominent attack surface. Vulnerabilities affecting this vendor skew strongly toward critical severity and recur across its product line through authentication and authorization bypasses, deserialization flaws, and cross-site scripting, reflecting the authentication-state and input-handling demands of web applications. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chimpgroup over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24389MEDIUM The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back | Jul 6, 2021 | 6.1 | 32 | NO | YES |
CVE-2022-0316CRITICAL The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme | Jan 23, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-11286CRITICAL The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to the plugin not properly verifying a user's iden | Mar 14, 2025 | 9.8 | 28 | NO | NO |
CVE-2024-11285CRITICAL The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 7.1. This is due to the plugin not properly val | Mar 14, 2025 | 9.8 | 28 | NO | NO |
CVE-2024-11284CRITICAL The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due to the plugin not properly val | Mar 14, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-32927CRITICAL Deserialization of Untrusted Data vulnerability in Chimpstudio FoodBakery wp-foodbakery allows Object Injection.This issue affects FoodBakery: from n/a through <= 3.3. | May 19, 2025 | 9.8 | 26 | NO | NO |
CVE-2024-12810HIGH The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on | Mar 14, 2025 | 8.1 | 24 | NO | NO |
CVE-2024-11283HIGH The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wp_ajax_google_api_login_callback function not | Mar 14, 2025 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chimpgroup.
Media articles that mention a CVE ID that affects a product developed by Chimpgroup — matched by CVE ID, not by vendor name.