Infolific's vulnerability footprint centers on a narrow set of WordPress-related plugins and extensions, including Add Any Extension to Pages, Enhanced Plugin Admin, and Real-Time Find and Replace utilities. The observed weakness class—cross-site request forgery—reflects the authentication and state-change protection challenges common to web-based administrative and content-management interfaces. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infolific over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28618HIGH Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Enhanced Plugin Admin plugin <= 1.16 versions. | Nov 12, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-50873HIGH Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Add Any Extension to Pages.This issue affects Add Any Extension to Pages: from n/a through 1.4. | Dec 28, 2023 | 8.8 | 24 | NO | NO |
CVE-2020-35135HIGH The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF. | Dec 11, 2020 | 8.8 | 23 | NO | NO |
CVE-2020-13641HIGH An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests | May 28, 2020 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infolific.
Media articles that mention a CVE ID that affects a product developed by Infolific — matched by CVE ID, not by vendor name.