Magnigenie develops WordPress plugins and extensions, including RestroPpress and WP Responsive Menu, that extend e-commerce and navigation functionality for website builders. The vendor's observed vulnerability surface centers on cross-site scripting issues arising from improper input neutralization in web-facing plugin code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Magnigenie over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66100MEDIUM Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: fr | Dec 18, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-69017MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnigenie RestroPress restropress allows Stored XSS.This issue affects Restro | Dec 30, 2025 | 6.5 | 21 | NO | NO |
CVE-2025-62129MEDIUM Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: fr | Dec 31, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-32553HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnigenie RestroPress restropress allows Reflected XSS.This issue affects Res | Apr 11, 2025 | 7.1 | 20 | NO | NO |
CVE-2021-24971MEDIUM The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of th | Feb 28, 2022 | 5.4 | 19 | NO | NO |
CVE-2024-35719MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagniGenie RestroPress allows Stored XSS.This issue affects RestroPress | Jun 8, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-32449MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in MagniGenie RestroPress.This issue affects RestroPress: from n/a through 3.1.2. | Apr 15, 2024 | 5.4 | 16 | NO | NO |
CVE-2025-31877MEDIUM Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: fr | Apr 1, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Magnigenie.
Media articles that mention a CVE ID that affects a product developed by Magnigenie — matched by CVE ID, not by vendor name.