Mijnpress develops a collection of WordPress plugins including Simple Add Pages or Posts, Admin Renamer Extended, Auto Prune Posts, and Mass Delete Unused Tags, presenting a narrow but recurring vulnerability surface centered on web application input handling. The observed weakness classes across these plugins cluster around cross-site request forgery and cross-site scripting, reflecting common challenges in WordPress plugin development where user input sanitization and session management require careful attention. Live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mijnpress over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27430HIGH Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Mass Delete Unused Tags plugin <= 2.0.0 versions. | May 18, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-27423HIGH Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Auto Prune Posts plugin <= 1.8.0 versions. | May 18, 2023 | 8.8 | 21 | NO | NO |
CVE-2016-10883MEDIUM The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users. | Aug 14, 2019 | 6.5 | 20 | NO | NO |
CVE-2019-14680MEDIUM The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF. | Aug 8, 2019 | 5.7 | 20 | NO | NO |
CVE-2024-13850MEDIUM The Simple add pages or posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.0 due to insufficient input sanitization a | Feb 8, 2025 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mijnpress.
Media articles that mention a CVE ID that affects a product developed by Mijnpress — matched by CVE ID, not by vendor name.