Madrasthemes develops WordPress plugins and themes, including job-manager integrations, page builders, and static content modules, where the observed vulnerability footprint centers on web-application input-handling and information-exposure issues such as cross-site scripting and sensitive data leakage. Treat this as a compact vendor profile reflecting a narrow product scope; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Madrasthemes over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-12328MEDIUM The MAS Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.7 due to insufficient input sanit | Jan 8, 2025 | 6.4 | 19 | NO | NO |
CVE-2024-9206MEDIUM The MAS Companies For WP Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in | Oct 18, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-8483MEDIUM The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.8 via the static_content() function. This makes it possi | Sep 25, 2024 | 6.5 | 18 | NO | NO |
CVE-2024-49233MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MadrasThemes MAS Elementor mas-addons-for-elementor allows DOM-Based XSS.This | Oct 18, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Madrasthemes.
Media articles that mention a CVE ID that affects a product developed by Madrasthemes — matched by CVE ID, not by vendor name.