Kevonadonis develops a focused web-based product, WP Abstracts, that sits in the WordPress ecosystem and has accumulated vulnerabilities centered on application-layer input handling. The recurring exposure reflects the product's web-facing nature and manifests in cross-site scripting and cross-site request forgery weaknesses typical of web-application plugins and extensions. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kevonadonis over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-48338HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager | Oct 22, 2025 | 7.5 | 24 | NO | NO |
CVE-2023-36517HIGH Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions. | Jul 11, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-29385MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions. | Jun 12, 2023 | 6.1 | 22 | NO | NO |
CVE-2025-32591HIGH Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Cross Site Request Forgery.This issue affects WP Abstracts: fro | Apr 9, 2025 | 7.1 | 19 | NO | NO |
CVE-2024-12386MEDIUM The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.3. This is due to missing nonce validation on multiple f | Feb 12, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-12385MEDIUM The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2. This is due to missing nonce validation on the wpabst | Jan 18, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-50411MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Stored XSS.T | Oct 29, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-44045MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Stored XSS.T | Oct 6, 2024 | 4.8 | 16 | NO | NO |
CVE-2023-28692MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.3 versions. | Aug 30, 2023 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kevonadonis.
Media articles that mention a CVE ID that affects a product developed by Kevonadonis — matched by CVE ID, not by vendor name.