Codeastrology develops a focused suite of WooCommerce plugins and add-ons for e-commerce customization, a niche but notable category of web-facing extensions exposed to direct user interaction and form submission. The vendor's vulnerabilities skew toward serious outcomes and frequently acquire public exploit code, concentrating in web-application security weaknesses including cross-site request forgery, cross-site scripting, missing authorization checks, and authorization-bypass conditions that are characteristic of plugin-layer access and input handling. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codeastrology over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1020CRITICAL The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (ava | Apr 18, 2022 | 9.8 | 55 | NO | YES |
CVE-2023-49153HIGH Cross-Site Request Forgery (CSRF) vulnerability in Saiful Islam Add to Cart Text Changer and Customize Button, Add Custom Icon.This issue affects Add to Cart Text Changer and Custo | Dec 18, 2023 | 8.8 | 21 | NO | NO |
CVE-2023-48768HIGH Cross-Site Request Forgery (CSRF) vulnerability in CodeAstrology Team Quantity Plus Minus Button for WooCommerce by CodeAstrology.This issue affects Quantity Plus Minus Button for | Dec 18, 2023 | 8.8 | 21 | NO | NO |
CVE-2024-10813HIGH The Product Table for WooCommerce by CodeAstrology (wooproducttable.com) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, | Nov 23, 2024 | 7.5 | 20 | NO | NO |
CVE-2023-4270MEDIUM The Min Max Control WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which co | Sep 11, 2023 | 6.1 | 18 | NO | NO |
CVE-2024-37554MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam UltraAddons Elementor Lite ultraaddons-elementor-lite allows DOM- | Jul 6, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-4866MEDIUM The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) plugin for WordPress is vulnerable to Sto | Jul 10, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-10696MEDIUM The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) plugin for WordPress is vulnerable to Ins | Nov 21, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codeastrology.
Media articles that mention a CVE ID that affects a product developed by Codeastrology — matched by CVE ID, not by vendor name.