Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gopiplus

First CVE: May 10, 2023Active for: 3 yearsTotal CVEs: 38
9.3
VTI Score
Low

Gopiplus develops a small portfolio of WordPress plugins and web components focused on content presentation and engagement—email subscription management, announcements, image carousels, and news tickers—that are installed across a modestly represented footprint of WordPress-based websites. The recurring vulnerability surface reflects application-layer input handling and output encoding practices typical of plugin development, with durable exposure through SQL injection, cross-site scripting, cross-site request forgery, and information disclosure in these content-delivery and subscription-management components. The vendor's disclosures cluster around these well-understood web-application weakness classes rather than memory-safety or cryptographic flaws, suggesting the technical debt common to incremental plugin development. Defenders deploying these plugins should treat input validation and output encoding patches as priority items within their WordPress maintenance cycles; current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
38
Total CVEs
More Total CVEs than 98% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gopiplus over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 10, 2023
3 years ago
Most Recent CVE
Mar 24, 2025
487 days ago

Products(27 total)

Top CVEs

Signals from CVEs in this vendor scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-46818CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopi Ramasamy Email posts to subscribers allows SQL Injection.This issue affec
Nov 3, 20239.829NONO
CVE-2023-5466HIGH
The Wp anything slider plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.1 due to insufficient escaping on the user
Nov 22, 20238.824NONO
CVE-2023-47671HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Gopi Ramasamy Vertical scroll recent.This issue affects Vertical scroll recent post: from n/a through 14.0.
Nov 18, 20238.824NONO
CVE-2023-4999HIGH
The Horizontal scrolling announcement plugin for WordPress is vulnerable to SQL Injection via the plugin's [horizontal-scrolling] shortcode in versions up to, and including, 9.2 du
Oct 20, 20238.824NONO
CVE-2023-25463HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Gopi Ramasamy WP tell a friend popup form plugin <= 7.1 versions.
Oct 3, 20238.824NONO
CVE-2023-5465HIGH
The Popup with fancybox plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 3.5 due to insufficient escaping on the use
Nov 22, 20238.822NONO
CVE-2023-5433MEDIUM
The Message ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.2 due to insufficient escaping on the user sup
Oct 31, 20236.521NONO
CVE-2024-11884MEDIUM
The Wp photo text slider 50 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-photo-slider' shortcode in all versions up to, and including, 8.1
Dec 14, 20246.420NONO
CVE-2023-5464MEDIUM
The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.1 due to insufficient escaping on
Oct 31, 20236.520NONO
CVE-2023-5439MEDIUM
The Wp photo text slider 50 plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.0 due to insufficient escaping on the
Oct 31, 20236.520NONO
View all 38 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products38 CVEs
82%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network38 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None20 (52.6%)
Unknown0 (0.0%)
Required18 (47.4%)
Privileges Required
Low20 (52.6%)
High13 (34.2%)
None5 (13.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gopiplus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gopiplus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gopiplus's Products

View all 2 CNAs →

Top CWEs