Followmedarling's vulnerability profile centers on web-accessible WordPress plugins and content-delivery integrations, with observed weaknesses clustering around cross-site scripting, sensitive-information exposure, and access-control issues typical of third-party web-application extensions. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Followmedarling over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-51529MEDIUM Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial | Aug 19, 2025 | 5.3 | 21 | NO | NO |
CVE-2023-40662HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jonk @ Follow me Darling Cookies and Content Security Policy.This issue affects Cookies and Content Secu | Nov 30, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-26536MEDIUM Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Jonk @ Follow me Darling Sp*tify Play Button for WordPress plugin <= 2.05 versions. | Apr 5, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-1840MEDIUM The Sp*tify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.07 due to insufficien | Apr 4, 2023 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Followmedarling.
Media articles that mention a CVE ID that affects a product developed by Followmedarling — matched by CVE ID, not by vendor name.