Infornweb develops WordPress plugins focused on content presentation and display functionality, including slider, carousel, and post-listing components that extend site authoring and publishing workflows. These plugins recurrently exhibit serious-outcome vulnerabilities concentrated in web-application input handling and access control, including cross-site scripting, cross-site request forgery, PHP remote file inclusion, and authorization bypass weaknesses that are endemic to WordPress plugin development. Live severity, exploitation activity, and vulnerability counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infornweb over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5815CRITICAL The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerab | Nov 22, 2023 | 9.8 | 41 | NO | YES |
CVE-2025-31082HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InfornWeb News & Blog Designer Pack blog-designer-pack allo | Apr 1, 2025 | 8.1 | 22 | NO | NO |
CVE-2022-4792MEDIUM The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to | Jan 30, 2023 | 5.4 | 20 | NO | NO |
CVE-2022-4749MEDIUM The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could a | Jan 30, 2023 | 5.4 | 20 | NO | NO |
CVE-2021-24729MEDIUM The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross- | Nov 23, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-24913MEDIUM The Logo Showcase with Slick Slider WordPress plugin before 2.0.1 does not have CSRF check in the lswss_save_attachment_data AJAX action, allowing attackers to make a logged in hig | Feb 28, 2022 | 4.3 | 18 | NO | NO |
CVE-2021-24730MEDIUM The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authentica | Feb 28, 2022 | 4.3 | 18 | NO | NO |
CVE-2025-4567MEDIUM The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate and escape some of its Widget options before outputting them | Jun 3, 2025 | 4.8 | 17 | NO | NO |
CVE-2024-23502MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in InfornWeb Posts List Designer by Category – List Category Posts Or Recent Post | Jan 31, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infornweb.
Media articles that mention a CVE ID that affects a product developed by Infornweb — matched by CVE ID, not by vendor name.