Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cm Wp

First CVE: Apr 5, 2021Active for: 5 yearsTotal CVEs: 20

Cm Wp's vulnerability footprint concentrates across a set of WordPress plugins and extensions including Social Slider Widget, Auto Featured Image, Clearfy, Woody Code Snippets, and Titan Anti-Spam & Security. The exposure reflects the typical attack surface of web-accessible WordPress components and their dependency on secure input handling and access control in third-party plugin environments. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
5.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cm Wp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 5, 2021
5 years ago
Most Recent CVE
May 15, 2025
435 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-0477HIGH
The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary file
Mar 13, 20238.827NONO
CVE-2021-24932MEDIUM
The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS b
Dec 13, 20216.121NONO
CVE-2022-2877MEDIUM
The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's
Sep 16, 20225.320NONO
CVE-2021-24196MEDIUM
The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and
Apr 5, 20215.418NONO
CVE-2024-13338MEDIUM
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin
Apr 12, 20254.316NONO
CVE-2024-35751MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Creative Motion, Will Bontrager Software, LLC Woody ad snippets allows
Jun 8, 20244.816NONO
CVE-2020-36759MEDIUM
The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.9. This is due to missing or incorrect nonce validati
Oct 20, 20234.316NONO
CVE-2024-10149MEDIUM
The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross
May 15, 20254.815NONO
CVE-2024-13337MEDIUM
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin
Apr 12, 20254.315NONO
CVE-2025-0717LOW
To exploit the vulnerability, it is necessary:
Mar 25, 20253.514NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
10%
80%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (20.0%)
Unknown0 (0.0%)
Required8 (80.0%)
Privileges Required
Low2 (20.0%)
High3 (30.0%)
None5 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cm Wp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cm Wp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cm Wp's Products

View all 3 CNAs →

Top CWEs