Hk1993 maintains a focused product line centered on the WP Online Users Stats plugin for WordPress, with a vulnerability profile rooted in application-layer input handling and request validation. The recurring weakness classes—cross-site request forgery and SQL injection—are characteristic of web-application components that process user input and database queries without sufficient sanitization or protection mechanisms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hk1993 over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-4966MEDIUM The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation with | Jun 6, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-4964MEDIUM The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter in all versions up to, and including, 1.0.0 due to insuffici | Jun 6, 2025 | 4.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hk1993.
Media articles that mention a CVE ID that affects a product developed by Hk1993 — matched by CVE ID, not by vendor name.