Cozmoslabs develops a narrow set of WordPress plugin-based solutions spanning membership management, content restriction, user profiling, and localization, each sitting within high-traffic content and commerce workflows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the accessible web-application nature of WordPress plugin code and the sensitive user and payment data these plugins protect. The exposure recurs across its product line through input-validation and authorization weakness classes—including cross-site scripting, cross-site request forgery, missing authorization checks, and authorization bypass mechanisms—that are characteristic of plugin ecosystems where tight integration with WordPress core and user-facing forms creates broad attack surface. Defenders should treat updates to these plugins as high-priority for any site running membership or content-gating logic, since compromises can expose subscriber data and payment information. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cozmoslabs over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6366CRITICAL The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality | Jul 29, 2024 | 9.1 | 53 | NO | YES |
CVE-2021-24527CRITICAL The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthoris | Aug 16, 2021 | 9.8 | 45 | NO | YES |
CVE-2022-3141HIGH The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific | Sep 19, 2022 | 8.8 | 40 | NO | YES |
CVE-2021-24170HIGH The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload | Apr 5, 2021 | 7.5 | 34 | NO | YES |
CVE-2022-0653MEDIUM The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url pa | Feb 24, 2022 | 6.1 | 32 | NO | YES |
CVE-2024-12919CRITICAL The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up | Jan 14, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-6695CRITICAL it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic | Jul 31, 2024 | 9.8 | 28 | NO | NO |
CVE-2021-24610MEDIUM The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with | Sep 27, 2021 | 4.8 | 28 | NO | YES |
CVE-2021-24728HIGH The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using th | Sep 13, 2021 | 8.8 | 28 | NO | NO |
CVE-2025-58592HIGH Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through | Nov 6, 2025 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cozmoslabs.
Media articles that mention a CVE ID that affects a product developed by Cozmoslabs — matched by CVE ID, not by vendor name.