Cm Wp's vulnerability footprint concentrates across a set of WordPress plugins and extensions including Social Slider Widget, Auto Featured Image, Clearfy, Woody Code Snippets, and Titan Anti-Spam & Security. The exposure reflects the typical attack surface of web-accessible WordPress components and their dependency on secure input handling and access control in third-party plugin environments. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cm Wp over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0477HIGH The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary file | Mar 13, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-24932MEDIUM The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS b | Dec 13, 2021 | 6.1 | 21 | NO | NO |
CVE-2022-2877MEDIUM The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's | Sep 16, 2022 | 5.3 | 20 | NO | NO |
CVE-2021-24196MEDIUM The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and | Apr 5, 2021 | 5.4 | 18 | NO | NO |
CVE-2024-13338MEDIUM The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin | Apr 12, 2025 | 4.3 | 16 | NO | NO |
CVE-2024-35751MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Creative Motion, Will Bontrager Software, LLC Woody ad snippets allows | Jun 8, 2024 | 4.8 | 16 | NO | NO |
CVE-2020-36759MEDIUM The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.9. This is due to missing or incorrect nonce validati | Oct 20, 2023 | 4.3 | 16 | NO | NO |
CVE-2024-10149MEDIUM The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross | May 15, 2025 | 4.8 | 15 | NO | NO |
CVE-2024-13337MEDIUM The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin | Apr 12, 2025 | 4.3 | 15 | NO | NO |
To exploit the vulnerability, it is necessary: | Mar 25, 2025 | 3.5 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cm Wp.
Media articles that mention a CVE ID that affects a product developed by Cm Wp — matched by CVE ID, not by vendor name.