Grandplugins develops a focused set of WordPress plugins including AVIF Uploader and Woo Quick View and Buy Now, targeting media handling and e-commerce functionality. The observed vulnerability pattern centers on cross-site scripting weaknesses in web-facing input handling, a durable signal for plugins that process user-supplied data in page generation contexts. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Grandplugins over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47657MEDIUM Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in GrandPlugins Direct Checkout – Quick View – Buy Now For WooCommerce plugin <= 1.5.8 versions. | Nov 14, 2023 | 4.8 | 18 | NO | NO |
CVE-2024-9238MEDIUM The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS | May 15, 2025 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Grandplugins.
Media articles that mention a CVE ID that affects a product developed by Grandplugins — matched by CVE ID, not by vendor name.