Noorsplugin develops a collection of WordPress plugins spanning video playback, e-commerce checkout integration, and media optimization, each introducing input-handling and request-validation surface into the WordPress application layer. The recurring vulnerability signature clusters around cross-site scripting, cross-site request forgery, and improper log handling—weaknesses characteristic of web plugin development where input sanitization and CSRF token management are critical. Current severity, exploitation status, and exposure scope are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Noorsplugin over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-49627HIGH Cross-Site Request Forgery (CSRF) vulnerability in Noor Alam WordPress Image SEO allows Cross Site Request Forgery.This issue affects WordPress Image SEO: from n/a through 1.1.4. | Oct 20, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-52143HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Naa986 WP Stripe Checkout.This issue affects WP Stripe Checkout: from n/a through 1.2.2.37. | Jan 5, 2024 | 7.5 | 21 | NO | NO |
CVE-2022-3987MEDIUM The Responsive Lightbox2 WordPress plugin before 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow user | Dec 19, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-3983MEDIUM The Checkout for PayPal WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow user | Dec 19, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-3937MEDIUM The Easy Video Player WordPress plugin before 1.2.2.3 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site | Dec 19, 2022 | 5.4 | 20 | NO | NO |
CVE-2023-51689MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in naa986 Easy Video Player allows Stored XSS.This issue affects Easy Video Playe | Feb 1, 2024 | 5.4 | 17 | NO | NO |
CVE-2022-3986MEDIUM The WP Stripe Checkout WordPress plugin before 1.2.2.21 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow use | Dec 19, 2022 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Noorsplugin.
Media articles that mention a CVE ID that affects a product developed by Noorsplugin — matched by CVE ID, not by vendor name.