Goprayer maintains a narrowly scoped portfolio centered on WordPress prayer plugins, which despite modest volume occupy a notable presence in the WordPress ecosystem and represent a prayer and devotional-content layer atop widely deployed sites. The durable signal in this vendor's disclosures is rooted in web-application input handling and request validation, with recurring vulnerability classes including cross-site scripting and cross-site request forgery that are characteristic of plugin-layer weaknesses in content management systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Goprayer over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3406HIGH The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them v | May 15, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-3405HIGH The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a C | May 15, 2024 | 7.6 | 20 | NO | NO |
CVE-2023-25705MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Go Prayer WP Prayer plugin <= 1.9.6 versions. | Apr 7, 2023 | 4.8 | 19 | NO | NO |
CVE-2024-4480MEDIUM The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change the | Jun 14, 2024 | 6.1 | 18 | NO | NO |
CVE-2021-24313MEDIUM The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests | Jun 1, 2021 | 5.4 | 18 | NO | NO |
CVE-2024-3407MEDIUM The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | May 15, 2024 | 5.3 | 16 | NO | NO |
CVE-2024-4751MEDIUM The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via | Jun 14, 2024 | 4.3 | 15 | NO | NO |
CVE-2021-4412MEDIUM The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5. This is due to missing or incorrect nonce validation on the | Jul 12, 2023 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Goprayer.
Media articles that mention a CVE ID that affects a product developed by Goprayer — matched by CVE ID, not by vendor name.