Fantasticplugins develops WordPress plugins centered on the Sumo Reward Points product, which extends e-commerce functionality through point-based loyalty systems. Observed vulnerabilities in this plugin cluster around PHP remote file inclusion issues, reflecting input-validation gaps characteristic of user-facing plugin code.
The number and severity of CVEs published that impact products developed by Fantasticplugins over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-32925CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FantasticPlugins SUMO Reward Points rewardsystem allows PHP | May 19, 2025 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fantasticplugins.
Media articles that mention a CVE ID that affects a product developed by Fantasticplugins — matched by CVE ID, not by vendor name.