Gravitymaster develops a narrowly focused WordPress plugin for e-commerce product inquiry management, which despite its niche scope sits in the request path of web-facing storefronts and form-handling workflows. The observed vulnerability profile centers on web-application input-handling weaknesses: cross-site scripting and cross-site request forgery issues that recur across the plugin's releases and reflect the challenges of sanitizing user input and enforcing token validation in web-facing WordPress components. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gravitymaster over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-49761HIGH Cross-Site Request Forgery (CSRF) vulnerability in Gravity Master Product Enquiry for WooCommerce.This issue affects Product Enquiry for WooCommerce: from n/a through 3.0. | Dec 18, 2023 | 8.8 | 21 | NO | NO |
CVE-2023-7151MEDIUM The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cr | Jan 16, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-47512MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions. | Nov 16, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-47696MEDIUM Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions. | Nov 13, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-6626MEDIUM The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform S | Jan 22, 2024 | 4.8 | 16 | NO | NO |
CVE-2023-6625MEDIUM The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin d | Jan 22, 2024 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gravitymaster.
Media articles that mention a CVE ID that affects a product developed by Gravitymaster — matched by CVE ID, not by vendor name.