Marcoingraiti maintains a niche product line focused on ActionWear Products Sync, a synchronization utility with a vulnerability footprint centered on information-disclosure and path-traversal weaknesses. These weaknesses reflect the risks inherent in file-access and error-handling logic within system-level synchronization tools; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Marcoingraiti over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-31619HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in marcoingraiti Actionwear products sync actionwear-products-sync allows SQL Inj | Apr 1, 2025 | 8.5 | 24 | NO | NO |
CVE-2025-49350MEDIUM Missing Authorization vulnerability in marcoingraiti Actionwear products sync actionwear-products-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This | Dec 9, 2025 | 4.3 | 17 | NO | NO |
CVE-2024-13535MEDIUM The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.3.2. This is due the composer-setup.php file being p | Feb 18, 2025 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Marcoingraiti.
Media articles that mention a CVE ID that affects a product developed by Marcoingraiti — matched by CVE ID, not by vendor name.