Hmplugin is a niche WordPress plugin vendor whose vulnerability exposure concentrates in a small set of donation and user-role management plugins such as JobWP, AidWP, and HM Multiple Roles. Its disclosures skew strongly toward critical-severity outcomes and recur through weakness classes including cross-site request forgery, exposure of sensitive information, improper privilege management, and missing authorization—patterns typical of WordPress plugins that handle payment processing and user capabilities without adequate input validation or access controls. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hmplugin over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29384CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects WordPress Job Board and Recruitment | Dec 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-50459CRITICAL Missing Authorization vulnerability in Hossni Mubarak AidWP wp-stripe-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AidWP: fro | Oct 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-47422HIGH Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin Accept Stripe Donation – AidWP plugin <= 3.1.5 versions. | Mar 14, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-24602HIGH The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page | Aug 23, 2021 | 8.8 | 27 | NO | NO |
CVE-2023-23705HIGH Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin WordPress Books Gallery plugin <= 4.4.8 versions. | May 23, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-48288HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects WordPress Job Board and | Dec 21, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hmplugin.
Media articles that mention a CVE ID that affects a product developed by Hmplugin — matched by CVE ID, not by vendor name.