Draftpress maintains a focused set of WordPress-oriented plugins, including Header Footer Code Manager and My Site Audit, that support website customization and auditing functions. The vulnerability exposure concentrates on application-layer input handling and request validation, with recurring issues including cross-site scripting, cross-site request forgery, and SQL injection that are characteristic of web-facing plugins. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Draftpress over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24791HIGH The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when vi | Nov 8, 2021 | 7.2 | 36 | NO | YES |
CVE-2022-0899MEDIUM The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cros | Jul 25, 2022 | 6.1 | 32 | NO | YES |
CVE-2023-39989HIGH Cross-Site Request Forgery (CSRF) vulnerability in 99robots Header Footer Code Manager plugin <= 1.1.34 versions. | Oct 3, 2023 | 8.8 | 24 | NO | NO |
CVE-2021-24445MEDIUM The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads i | Aug 16, 2021 | 5.5 | 20 | NO | NO |
CVE-2022-0710MEDIUM The Header Footer Code Manager plugin <= 1.1.16 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter. | Feb 24, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Draftpress.
Media articles that mention a CVE ID that affects a product developed by Draftpress — matched by CVE ID, not by vendor name.