Internet Formation maintains a narrow portfolio of WordPress plugins, including advanced search and portfolio components, that serve website customization and content-management functions. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Internet Formation over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9796CRITICAL The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQ | Oct 10, 2024 | 9.8 | 42 | NO | YES |
CVE-2022-47447HIGH Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WordPress WP-Advanced-Search plugin <= 3.3.8 versions. | May 24, 2023 | 8.8 | 25 | NO | NO |
CVE-2020-12104HIGH The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute | May 5, 2020 | 8.8 | 22 | NO | NO |
CVE-2024-13851MEDIUM The Modal Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.7.4.2 due to insufficient input sanitization and outpu | Feb 28, 2025 | 4.8 | 16 | NO | NO |
The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform | Mar 25, 2025 | 3.5 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Internet Formation.
Media articles that mention a CVE ID that affects a product developed by Internet Formation — matched by CVE ID, not by vendor name.