Gopiplus develops a small portfolio of WordPress plugins and web components focused on content presentation and engagement—email subscription management, announcements, image carousels, and news tickers—that are installed across a modestly represented footprint of WordPress-based websites. The recurring vulnerability surface reflects application-layer input handling and output encoding practices typical of plugin development, with durable exposure through SQL injection, cross-site scripting, cross-site request forgery, and information disclosure in these content-delivery and subscription-management components. The vendor's disclosures cluster around these well-understood web-application weakness classes rather than memory-safety or cryptographic flaws, suggesting the technical debt common to incremental plugin development. Defenders deploying these plugins should treat input validation and output encoding patches as priority items within their WordPress maintenance cycles; current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gopiplus over time
Signals from CVEs in this vendor scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46818CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopi Ramasamy Email posts to subscribers allows SQL Injection.This issue affec | Nov 3, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-5466HIGH The Wp anything slider plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.1 due to insufficient escaping on the user | Nov 22, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-47671HIGH Cross-Site Request Forgery (CSRF) vulnerability in Gopi Ramasamy Vertical scroll recent.This issue affects Vertical scroll recent post: from n/a through 14.0. | Nov 18, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-4999HIGH The Horizontal scrolling announcement plugin for WordPress is vulnerable to SQL Injection via the plugin's [horizontal-scrolling] shortcode in versions up to, and including, 9.2 du | Oct 20, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-25463HIGH Cross-Site Request Forgery (CSRF) vulnerability in Gopi Ramasamy WP tell a friend popup form plugin <= 7.1 versions. | Oct 3, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-5465HIGH The Popup with fancybox plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 3.5 due to insufficient escaping on the use | Nov 22, 2023 | 8.8 | 22 | NO | NO |
CVE-2023-5433MEDIUM The Message ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.2 due to insufficient escaping on the user sup | Oct 31, 2023 | 6.5 | 21 | NO | NO |
CVE-2024-11884MEDIUM The Wp photo text slider 50 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-photo-slider' shortcode in all versions up to, and including, 8.1 | Dec 14, 2024 | 6.4 | 20 | NO | NO |
CVE-2023-5464MEDIUM The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.1 due to insufficient escaping on | Oct 31, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-5439MEDIUM The Wp photo text slider 50 plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.0 due to insufficient escaping on the | Oct 31, 2023 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (38 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gopiplus.
Media articles that mention a CVE ID that affects a product developed by Gopiplus — matched by CVE ID, not by vendor name.