Designmodo's vulnerability profile centers on WordPress plugins, particularly its maintenance-mode and card-building tools, which expose web applications to common plugin-layer weaknesses. The durable signal reflects input handling and authorization gaps characteristic of web-facing extensions, including cross-site scripting, improper input validation, information exposure, and server-side request forgery. Current severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Designmodo over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-18598MEDIUM The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php. | Sep 10, 2019 | 6.1 | 32 | NO | YES |
CVE-2022-40700CRITICAL Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch S | Jan 19, 2024 | 9.8 | 29 | NO | NO |
CVE-2018-20156HIGH The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throughout a multisite network. | Dec 14, 2018 | 7.2 | 23 | NO | NO |
CVE-2018-20155MEDIUM The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings. | Dec 14, 2018 | 4.3 | 18 | NO | NO |
CVE-2018-20154MEDIUM The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses. | Dec 14, 2018 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Designmodo.
Media articles that mention a CVE ID that affects a product developed by Designmodo — matched by CVE ID, not by vendor name.