Hwk maintains a WordPress plugin focused on automatic redirection to similar posts, with a vulnerability profile centered on the application-layer handling of user input and page generation. The durable signal centers on cross-site scripting weaknesses in the plugin's output-neutralization logic. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hwk over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0509MEDIUM The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘request’ parameter in all versions up to, and including, 1.0. | Feb 5, 2024 | 6.1 | 20 | NO | NO |
CVE-2023-40206MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in hwk-fr WP 404 Auto Redirect to Similar Post plugin <= 1.0.3 versions. | Sep 4, 2023 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hwk.
Media articles that mention a CVE ID that affects a product developed by Hwk — matched by CVE ID, not by vendor name.