Ilghera's vulnerability footprint is concentrated in web-facing applications—specifically its MailUp Auto Subscription and WooCommerce Support System products—where the recurring issues center on cross-site request forgery and SQL injection weaknesses. These application-layer input-handling and request-validation flaws are characteristic of web platforms that process untrusted user input. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ilghera over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41685CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ilGhera Woocommerce Support System allows SQL Injection.This issue affects Woo | Nov 6, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-41686MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in ilGhera Woocommerce Support System allows Cross Site Request Forgery.This issue affects Woocommerce Support System: from n/a thro | Dec 13, 2024 | 6.5 | 21 | NO | NO |
CVE-2024-13521MEDIUM The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce | Jan 28, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ilghera.
Media articles that mention a CVE ID that affects a product developed by Ilghera — matched by CVE ID, not by vendor name.