Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Goprayer

First CVE: Jun 1, 2021Active for: 5 yearsTotal CVEs: 8

Goprayer maintains a narrowly scoped portfolio centered on WordPress prayer plugins, which despite modest volume occupy a notable presence in the WordPress ecosystem and represent a prayer and devotional-content layer atop widely deployed sites. The durable signal in this vendor's disclosures is rooted in web-application input handling and request validation, with recurring vulnerability classes including cross-site scripting and cross-site request forgery that are characteristic of plugin-layer weaknesses in content management systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Goprayer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 1, 2021
5 years ago
Most Recent CVE
Jun 14, 2024
771 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-3406HIGH
The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them v
May 15, 20248.824NONO
CVE-2024-3405HIGH
The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a C
May 15, 20247.620NONO
CVE-2023-25705MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Go Prayer WP Prayer plugin <= 1.9.6 versions.
Apr 7, 20234.819NONO
CVE-2024-4480MEDIUM
The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change the
Jun 14, 20246.118NONO
CVE-2021-24313MEDIUM
The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests
Jun 1, 20215.418NONO
CVE-2024-3407MEDIUM
The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
May 15, 20245.316NONO
CVE-2024-4751MEDIUM
The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via
Jun 14, 20244.315NONO
CVE-2021-4412MEDIUM
The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5. This is due to missing or incorrect nonce validation on the
Jul 12, 20234.315NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
75%
25%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (25.0%)
Network6 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (12.5%)
Unknown0 (0.0%)
Required7 (87.5%)
Privileges Required
Low3 (37.5%)
High2 (25.0%)
None3 (37.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Goprayer.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Goprayer — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Goprayer's Products

View all 3 CNAs →

Top CWEs