One Click Plugin Updater Project maintains a WordPress plugin focused on automating plugin updates, a narrow product with typical prevalence in the WordPress ecosystem. Observed vulnerabilities center on cross-site request forgery (CSRF) weaknesses in the plugin's administrative functions, a class of flaw common to web-based management interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by One Click Plugin Updater Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1791HIGH The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin cha | Jun 13, 2022 | 8.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by One Click Plugin Updater Project.
Media articles that mention a CVE ID that affects a product developed by One Click Plugin Updater Project — matched by CVE ID, not by vendor name.