Crudlab develops browser-focused plugins and WordPress extensions, including Jazz Popups and WP Like Button, with a vulnerability profile centered on web-application input handling and authentication gaps. The recurring weakness classes—cross-site request forgery, cross-site scripting, and missing authentication for critical functions—are characteristic of client-side and plugin-level implementations where input validation and session protection demand close attention. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Crudlab over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13344MEDIUM An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function | Jul 5, 2019 | 5.3 | 53 | NO | YES |
CVE-2023-40199HIGH Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab WP Like Button plugin <= 1.7.0 versions. | Oct 3, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-32966MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab Jazz Popups leads to Stored XSS.This issue affects Jazz Popups: from n/a through 1.8.7. | Nov 7, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-32965MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CRUDLab Jazz Popups plugin <= 1.8.7 versions. | Jul 18, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-47820MEDIUM Missing Authorization vulnerability in CRUDLab WP Like Button allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Like Button: from n/a th | Dec 9, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Crudlab.
Media articles that mention a CVE ID that affects a product developed by Crudlab — matched by CVE ID, not by vendor name.