Never5 develops a narrow set of WordPress-oriented plugins, including Related Posts, Post Connector, and Download Monitor, which sit in the content-management and plugin ecosystem. The vendor's disclosures concentrate on web-application input-handling weaknesses such as cross-site scripting and cross-site request forgery, which are characteristic of server-side template and form-processing logic, and the plugin portfolio frequently acquires public exploit tooling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Never5 over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3506MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3. | Oct 14, 2022 | 5.4 | 30 | NO | YES |
CVE-2021-24482MEDIUM The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading | Jul 19, 2021 | 4.8 | 19 | NO | NO |
CVE-2021-24180MEDIUM Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'la | Apr 5, 2021 | 5.4 | 18 | NO | NO |
CVE-2015-9362MEDIUM The Post Connector plugin before 1.0.4 for WordPress has XSS via add_query_arg() and remove_query_arg(). | Aug 28, 2019 | 6.1 | 17 | NO | NO |
CVE-2015-9361MEDIUM The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg(). | Aug 28, 2019 | 6.1 | 17 | NO | NO |
CVE-2015-9296MEDIUM The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg. | Aug 13, 2019 | 6.1 | 17 | NO | NO |
CVE-2024-0592MEDIUM The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect no | Mar 13, 2024 | 5.4 | 16 | NO | NO |
CVE-2023-28931MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Never5 Post Connector plugin <= 1.0.9 versions. | Aug 8, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Never5.
Media articles that mention a CVE ID that affects a product developed by Never5 — matched by CVE ID, not by vendor name.