Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ngothang

First CVE: Sep 8, 2024Active for: 2 yearsTotal CVEs: 8

Ngothang maintains a narrowly scoped vulnerability footprint centered on the WP Multitasking plugin, a web application component whose disclosures cluster around input-handling and request-validation weaknesses such as cross-site scripting and cross-site request forgery. These are characteristic flaws in web-based WordPress plugins where insufficient input sanitization and CSRF protections expose users and site operators to client-side attacks. Current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
4.5
Avg CVSS Score
Higher Avg CVSS Score than 7% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ngothang over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 8, 2024
22 months ago
Most Recent CVE
Apr 9, 2025
471 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-6859MEDIUM
The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is
Sep 8, 20245.417NONO
CVE-2024-8189MEDIUM
The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpmt_menu_name’ parameter in all versions up to, and including, 0.1.17
Sep 28, 20244.816NONO
CVE-2024-6860MEDIUM
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix settings, which could allow attackers to make logged admins perform
Apr 9, 20254.315NONO
CVE-2024-6857MEDIUM
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body Script Settings, which could allow attackers to make logged
Apr 9, 20254.315NONO
CVE-2024-6856MEDIUM
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them
Sep 8, 20244.315NONO
CVE-2024-6855MEDIUM
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform such action via a
Sep 8, 20244.315NONO
CVE-2024-6853MEDIUM
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action vi
Sep 8, 20244.315NONO
CVE-2024-6852MEDIUM
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them
Sep 8, 20244.315NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required8 (100.0%)
Privileges Required
Low1 (12.5%)
High1 (12.5%)
None6 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ngothang.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ngothang — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ngothang's Products

View all 2 CNAs →

Top CWEs