Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lesterchan

First CVE: Nov 30, 2011Active for: 15 yearsTotal CVEs: 10
7.6
VTI Score
Low

Lesterchan develops a narrow portfolio of WordPress plugins focused on content management and user engagement features, including post ratings, download management, and view tracking components widely integrated into WordPress installations. Vulnerabilities affecting these plugins skew toward serious outcomes and recur through input-handling and privilege-control weakness classes including cross-site scripting, cross-site request forgery, authentication bypass, and code injection, reflecting the common risks of plugin-based extensibility in WordPress environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lesterchan over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 30, 2011
14 years ago
Most Recent CVE
Oct 6, 2024
656 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-40332CRITICAL
Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Functionality Misuse.This issue affects WP-PostRatings: from n/a through 1.91.
Jun 4, 20249.826NONO
CVE-2013-3252MEDIUM
Cross-site request forgery (CSRF) vulnerability in the options admin page in the WP-PostViews plugin before 1.63 for WordPress allows remote attackers to hijack the authentication
Apr 10, 20146.822NONO
CVE-2024-47341HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lester Chan WP-DownloadManager wp-downloadmanager allows Reflected XSS.This is
Oct 6, 20247.121NONO
CVE-2013-2697MEDIUM
Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users f
Apr 19, 20136.821NONO
CVE-2011-4646MEDIUM
SQL injection vulnerability in wp-postratings.php in the WP-PostRatings plugin 1.50, 1.61, and probably other versions before 1.62 for WordPress allows remote authenticated users w
Nov 30, 20116.019NONO
CVE-2011-10006MEDIUM
A vulnerability was found in GamerZ WP-PostRatings up to 1.64. It has been classified as problematic. This affects an unknown part of the file wp-postratings.php. The manipulation
Apr 8, 20246.118NONO
CVE-2023-5560MEDIUM
The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputting its content on the page, which allows unauthenticated use
Nov 27, 20236.118NONO
CVE-2024-39659MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Stored XSS.This issue affect
Aug 1, 20245.417NONO
CVE-2023-3721MEDIUM
The WP-EMail WordPress plugin before 2.69.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scr
Aug 14, 20234.817NONO
CVE-2021-25117MEDIUM
The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-option
Jan 16, 20244.816NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
80%
10%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (70.0%)
Unknown3 (30.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (70.0%)
High0 (0.0%)
Unknown3 (30.0%)
User Interaction
None1 (10.0%)
Unknown3 (30.0%)
Required6 (60.0%)
Privileges Required
Low1 (10.0%)
High2 (20.0%)
None4 (40.0%)
Unknown3 (30.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lesterchan.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lesterchan — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lesterchan's Products

View all 4 CNAs →

Top CWEs