Mohsinrasool's vulnerability footprint centers on a collection of WordPress plugin products, including PayPal integration shortcodes, image slideshow functionality, and Bootstrap accordion components. The observed weakness class reflects standard web application input-handling risks, with cross-site scripting vulnerabilities identified across the plugin portfolio. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mohsinrasool over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5447MEDIUM The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege us | Jun 21, 2024 | 4.8 | 17 | NO | NO |
CVE-2024-12722MEDIUM The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a p | May 15, 2025 | 5.4 | 16 | NO | NO |
CVE-2024-5448MEDIUM The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not validate and escape some of its shortcode attributes before outputting them b | Jun 21, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-11221MEDIUM The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as adm | May 15, 2025 | 4.8 | 15 | NO | NO |
CVE-2024-3065MEDIUM The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and inc | May 23, 2024 | 4.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mohsinrasool.
Media articles that mention a CVE ID that affects a product developed by Mohsinrasool — matched by CVE ID, not by vendor name.