Essentialplugin develops a modestly represented suite of WordPress plugins focused on media galleries, audio players, banners, and content display, which expose a narrow but meaningful attack surface given their web-facing role. The recurring vulnerability signal centers on web-application input-handling weaknesses including cross-site scripting, cross-site request forgery, and code injection, alongside insufficient input neutralization during page generation—issues typical of plugin-layer WordPress integrations where user input and administrative functions intersect. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Essentialplugin over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38077HIGH Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversions plugin <= 2.2.1 versions. | Mar 29, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-2115MEDIUM The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting | Jul 25, 2022 | 6.1 | 22 | NO | NO |
CVE-2025-13612MEDIUM The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `aigpl-gallery-album` shortcode in all versions up to, | Feb 19, 2026 | 6.4 | 21 | NO | NO |
CVE-2024-4194HIGH The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0. This is due to the soft | Jun 6, 2024 | 7.3 | 21 | NO | NO |
CVE-2022-45818MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Hero Banner Ultimate plugin <= 1.3.4 versions. | May 4, 2023 | 5.4 | 20 | NO | NO |
CVE-2021-24883MEDIUM The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform | Nov 29, 2021 | 5.4 | 20 | NO | NO |
CVE-2025-22305MEDIUM Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Essential Plugin Hero Banner Ultimate hero-banner-ultimate | Jan 7, 2025 | 6.5 | 19 | NO | NO |
CVE-2022-4791MEDIUM The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape one of its shortcode attributes, which could allow users with | Feb 21, 2023 | 5.4 | 19 | NO | NO |
CVE-2022-4824MEDIUM The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users | Feb 6, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-38516MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Audio Player with Playlist Ultimate plugin <= 1.2.2 versions. | Sep 3, 2023 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Essentialplugin.
Media articles that mention a CVE ID that affects a product developed by Essentialplugin — matched by CVE ID, not by vendor name.