Heroplugins develops plugin software centered on the Hero Maps Premium product, where vulnerabilities reflect common application-layer input-handling issues including cross-site scripting and SQL injection. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Heroplugins over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19134MEDIUM The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter because it fails to sufficiently sanitize u | Feb 26, 2020 | 6.1 | 31 | NO | YES |
CVE-2024-13781MEDIUM The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to, and including, 2.3.9 due to insufficient escaping on the u | Mar 7, 2025 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Heroplugins.
Media articles that mention a CVE ID that affects a product developed by Heroplugins — matched by CVE ID, not by vendor name.