Futuriowp's vulnerability footprint centers on a single WordPress extension product, Futurio Extra, that operates within the widely installed WordPress ecosystem and presents a web-application attack surface. The recurring weaknesses—cross-site scripting, authorization bypass, CSRF, information exposure, and SQL injection—reflect the input-handling and access-control challenges inherent to plugin development and underscore the importance of validating all user-supplied data and enforcing proper session management. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Futuriowp over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-40201HIGH Cross-Site Request Forgery (CSRF) vulnerability in FuturioWP Futurio Extra plugin <= 1.8.4 versions leads to activation of arbitrary plugin. | Oct 3, 2023 | 8.8 | 26 | NO | NO |
CVE-2021-25110MEDIUM The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user's email address. | Feb 14, 2022 | 4.3 | 18 | NO | NO |
CVE-2024-53802MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FuturioWP Futurio Extra futurio-extra allows Stored XSS.This issue affects Fut | Dec 6, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-50446MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FuturioWP Futurio Extra futurio-extra.This issue affects Futurio Extra: from n | Oct 28, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-5646MEDIUM The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘header_size’ attribute within the Advanced Text Block widget in all versions up to, and | Jun 11, 2024 | 5.4 | 16 | NO | NO |
The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high privilege users to extract data from the database as well as | Feb 14, 2022 | 2.7 | 16 | NO | NO |
CVE-2024-10695MEDIUM The Futurio Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.0.13 via the 'elementor-template' shortcode due to insufficient | Nov 12, 2024 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Futuriowp.
Media articles that mention a CVE ID that affects a product developed by Futuriowp — matched by CVE ID, not by vendor name.