Ngothang maintains a narrowly scoped vulnerability footprint centered on the WP Multitasking plugin, a web application component whose disclosures cluster around input-handling and request-validation weaknesses such as cross-site scripting and cross-site request forgery. These are characteristic flaws in web-based WordPress plugins where insufficient input sanitization and CSRF protections expose users and site operators to client-side attacks. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ngothang over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6859MEDIUM The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is | Sep 8, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-8189MEDIUM The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpmt_menu_name’ parameter in all versions up to, and including, 0.1.17 | Sep 28, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-6860MEDIUM The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix settings, which could allow attackers to make logged admins perform | Apr 9, 2025 | 4.3 | 15 | NO | NO |
CVE-2024-6857MEDIUM The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body Script Settings, which could allow attackers to make logged | Apr 9, 2025 | 4.3 | 15 | NO | NO |
CVE-2024-6856MEDIUM The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them | Sep 8, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-6855MEDIUM The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform such action via a | Sep 8, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-6853MEDIUM The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action vi | Sep 8, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-6852MEDIUM The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them | Sep 8, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ngothang.
Media articles that mention a CVE ID that affects a product developed by Ngothang — matched by CVE ID, not by vendor name.