Fullworksplugins develops a suite of WordPress plugins spanning event management, payment processing, user authentication, and contact forms that are deployed across numerous small-to-medium web properties. The vendor's vulnerability profile clusters around web-application input handling and session-management weaknesses—including cross-site scripting, cross-site request forgery, and information disclosure—and exhibits a tendency toward public exploit availability, consistent with the appeal of widely installed and often-unmaintained WordPress extensions. Defenders should prioritize patching these plugins where deployed and monitor vendor releases for security updates; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fullworksplugins over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23491MEDIUM The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' acti | Jan 20, 2023 | 6.1 | 31 | NO | YES |
CVE-2017-18536MEDIUM The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS. | Aug 21, 2019 | 6.1 | 28 | NO | YES |
CVE-2025-4302MEDIUM The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encodi | Jul 17, 2025 | 5.3 | 25 | NO | YES |
CVE-2023-25713MEDIUM Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | Apr 7, 2023 | 6.1 | 21 | NO | NO |
CVE-2022-37339MEDIUM Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin <= 2.0.5 at WordPress. | Sep 23, 2022 | 5.4 | 20 | NO | NO |
CVE-2023-23889MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | Apr 25, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-23885MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions. | Apr 7, 2023 | 5.4 | 19 | NO | NO |
CVE-2017-1000226MEDIUM Stop User Enumeration 1.3.8 allows user enumeration via the REST API | Nov 17, 2017 | 5.3 | 19 | NO | NO |
CVE-2023-1554MEDIUM The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored | May 2, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-25702MEDIUM Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | Apr 7, 2023 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fullworksplugins.
Media articles that mention a CVE ID that affects a product developed by Fullworksplugins — matched by CVE ID, not by vendor name.