Nsthemes develops a focused portfolio of WordPress and WooCommerce plugins including Advanced Social Pixel, NS Coupon to Become Customer, and NS Watermark for WooCommerce, which extend e-commerce and social integration functionality for online merchants. The durable signal in disclosures centers on cross-site scripting vulnerabilities arising from improper input neutralization during web page generation, a recurring weakness class in plugin-based web applications where user-supplied data flows directly into rendered output. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nsthemes over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0989HIGH An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious | Apr 11, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-24381MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NsThemes Advanced Social Pixel plugin <= 2.1.1 versions. | Mar 20, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-27422MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NsThemes NS Coupon To Become Customer plugin <= 1.2.2 versions. | Aug 8, 2023 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nsthemes.
Media articles that mention a CVE ID that affects a product developed by Nsthemes — matched by CVE ID, not by vendor name.