I Plugins maintains a narrowly focused product portfolio centered on the WHMCS Bridge integration, which extends functionality for a widely deployed web hosting and client management platform. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by I Plugins over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25112MEDIUM The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scrip | Feb 28, 2022 | 6.1 | 31 | NO | YES |
CVE-2021-4074MEDIUM The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows att | Jan 18, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by I Plugins.
Media articles that mention a CVE ID that affects a product developed by I Plugins — matched by CVE ID, not by vendor name.