Getigniteup's vulnerability profile centers on its IgniteUp platform and exhibits a pattern of application-layer security issues, particularly cross-site scripting, missing authentication controls on critical functions, and cross-site request forgery weaknesses. These are characteristic of web-application input-handling and access-control gaps that defenders should address in standard web-application security reviews; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getigniteup over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17237HIGH includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF. | Nov 12, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-17234HIGH includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion. | Nov 12, 2019 | 7.5 | 24 | NO | NO |
CVE-2022-0898MEDIUM The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't have the unfiltered_html capability, which could lead to Stored | May 9, 2022 | 5.4 | 20 | NO | NO |
CVE-2019-17236MEDIUM includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS. | Nov 12, 2019 | 6.1 | 20 | NO | NO |
CVE-2019-17235MEDIUM includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure. | Nov 12, 2019 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getigniteup.
Media articles that mention a CVE ID that affects a product developed by Getigniteup — matched by CVE ID, not by vendor name.