Ifeelweb's vulnerability footprint concentrates in a small set of web-based tools, particularly its affiliate and notification plugins, with recurring exposure patterns centered on web-application input handling and request validation—specifically cross-site request forgery, code injection, and cross-site scripting weaknesses. These classes are typical of plugins that process user input and generate dynamic content without sufficient sanitization or origin verification. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ifeelweb over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4325MEDIUM The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scrip | Jan 9, 2023 | 6.1 | 30 | NO | YES |
CVE-2023-27417HIGH Cross-Site Request Forgery (CSRF) vulnerability in Timo Reith Affiliate Super Assistent plugin <= 1.5.1 versions. | Nov 12, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-8478HIGH The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allow | Sep 10, 2024 | 7.3 | 22 | NO | NO |
CVE-2023-47766MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Reith Post Status Notifier Lite plugin <= 1.11.0 versions. | Nov 22, 2023 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ifeelweb.
Media articles that mention a CVE ID that affects a product developed by Ifeelweb — matched by CVE ID, not by vendor name.