Convertplug develops a WordPress plugin focused on lead-capture and conversion-optimization functionality, with its reported vulnerability exposure centered on the core Convertplus product. The durable signal reflects access-control weaknesses, particularly missing authorization checks that affect plugin functionality. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Convertplug over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13800HIGH The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cp_dismiss_no | Feb 12, 2025 | 8.1 | 25 | NO | NO |
CVE-2019-15863HIGH The ConvertPlus plugin before 3.4.5 for WordPress has an unintended account creation (with the none role) via a request for variants. | Sep 3, 2019 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Convertplug.
Media articles that mention a CVE ID that affects a product developed by Convertplug — matched by CVE ID, not by vendor name.