Codexpert's modest footprint spans a small set of web-based products including WC Affiliate, CodeSigner, and Search Logger, with exposures clustered around web application input handling and data-management vulnerabilities. The recurring weakness classes center on cross-site scripting, SQL injection, deserialization of untrusted data, and missing authorization controls, reflecting the input-validation and access-control demands of server-side web applications. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codexpert over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4371CRITICAL The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object Injection in all versions up to | Jun 13, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-12336MEDIUM The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'export_all_da | Mar 15, 2025 | 6.5 | 20 | NO | NO |
CVE-2022-3131HIGH The Search Logger WordPress plugin through 0.9 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high | Oct 17, 2022 | 7.2 | 19 | NO | NO |
CVE-2024-12321HIGH The WC Affiliate WordPress plugin through 2.3.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which c | Jan 27, 2025 | 7.1 | 18 | NO | NO |
CVE-2024-12334MEDIUM The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter in all versions up to, and includi | Jan 26, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codexpert.
Media articles that mention a CVE ID that affects a product developed by Codexpert — matched by CVE ID, not by vendor name.