Obtaininfotech offers a focused line of WordPress multisite management tools, including content copying and user synchronization utilities, with its vulnerability profile centered on web application input-handling issues such as cross-site scripting. Treat this as a compact vendor profile; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Obtaininfotech over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25039MEDIUM The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.0 does not sanitise and escape the wmcc_content_type, wmcc_source_blog and wmcc_record_per_page parameter | Mar 7, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-25038MEDIUM The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them | Mar 7, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-0503MEDIUM The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.2 does not sanitise and escape the s parameter before outputting it back in an attribute, leading to a Re | Mar 14, 2022 | 6.1 | 21 | NO | NO |
CVE-2024-38673HIGH Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Obtain Infotech Multisite Content Copier/Updater allows Reflected XSS.T | Jul 20, 2024 | 7.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Obtaininfotech.
Media articles that mention a CVE ID that affects a product developed by Obtaininfotech — matched by CVE ID, not by vendor name.