Incsub develops a focused portfolio of WordPress plugins and themes that serve community-building, lead-generation, and performance-optimization functions, positioning the vendor in a large ecosystem of widely deployed web applications. The vendor's vulnerability footprint clusters around web application and plugin-specific weakness classes—notably cross-site scripting, unrestricted file uploads, cross-site request forgery, path traversal, and SQL injection—reflecting the input-handling and access-control demands of user-facing WordPress extensions. A meaningful share of these vulnerabilities reach serious severity outcomes, driven by the attack surface that web-facing forms, content uploads, and database queries present. Defenders should track this vendor's plugin updates closely and treat remediation of affected installations as routine given the breadth of WordPress deployment. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Incsub over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4596CRITICAL The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_im | Aug 30, 2023 | 9.8 | 40 | NO | YES |
CVE-2024-31077HIGH Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain a | Apr 23, 2024 | 7.2 | 37 | NO | NO |
CVE-2025-6463HIGH The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in th | Jul 2, 2025 | 8.8 | 32 | NO | NO |
CVE-2026-56071HIGH Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions. | Jun 25, 2026 | 7.1 | 31 | NO | NO |
CVE-2023-1478CRITICAL The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the p | Apr 10, 2023 | 9.8 | 29 | NO | NO |
CVE-2019-11872HIGH The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation g | May 29, 2019 | 8.8 | 28 | NO | NO |
CVE-2025-6464HIGH The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via | Jul 2, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-43118HIGH Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1. | Nov 1, 2024 | 8.8 | 23 | NO | NO |
CVE-2019-9568MEDIUM The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the att | Mar 4, 2019 | 6.5 | 23 | NO | NO |
CVE-2024-7389HIGH The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This | Aug 2, 2024 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Incsub.
Media articles that mention a CVE ID that affects a product developed by Incsub — matched by CVE ID, not by vendor name.