Joomunited develops a focused suite of WordPress plugins and extensions that extend content management and data-handling capabilities, achieving prominence despite a narrowly scoped product portfolio. The vendor's vulnerability exposure recurs across plugins such as WP Meta SEO, WP Table Manager, WP Smart Editor, WP File Download, and WP Latest Posts through weakness classes centered on web application security primitives: cross-site scripting, missing authorization, cross-site request forgery, unsafe deserialization, and metadata exposure. These flaws reflect the challenges of building extensible WordPress components that interact with user input, administrative functions, and sensitive data while respecting WordPress's permission model. The exposure profile shows a moderate tendency toward serious-severity outcomes and a low tendency toward public exploit availability, while defenders should prioritize patching exposed WordPress installations running these plugins and ensure strict access controls on administrative functions. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joomunited over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9643HIGH The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, and including, 4.5.18. | Jun 24, 2026 | 7.2 | 32 | NO | NO |
CVE-2026-9620MEDIUM The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, and including, 5.0.11. Thi | Jun 24, 2026 | 6.4 | 30 | NO | NO |
CVE-2026-11370MEDIUM The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' parameter. This makes it possible | Jun 24, 2026 | 6.4 | 30 | NO | NO |
CVE-2023-0876MEDIUM The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redi | Mar 20, 2023 | 6.1 | 30 | NO | YES |
CVE-2023-0875HIGH The WP Meta SEO WordPress plugin before 4.5.3 does not properly sanitize and escape inputs into SQL queries, leading to a blind SQL Injection vulnerability that can be exploited by | Mar 20, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-1381HIGH The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. F | Apr 10, 2023 | 8.8 | 27 | NO | NO |
CVE-2024-25909HIGH Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2. | Feb 26, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-6961MEDIUM The WP Meta SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Referer’ header in all versions up to, and including, 4.5.12 due to insufficient input sa | May 2, 2024 | 6.1 | 21 | NO | NO |
CVE-2025-5034HIGH The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | Jun 21, 2025 | 7.1 | 20 | NO | NO |
CVE-2024-13374MEDIUM The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in all versions up to, and includ | Feb 12, 2025 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joomunited.
Media articles that mention a CVE ID that affects a product developed by Joomunited — matched by CVE ID, not by vendor name.