Onedesigns develops a small portfolio of WordPress-oriented plugins, with observed vulnerabilities centered on client-side web application security issues such as cross-site scripting and cross-site request forgery. The recurring exposure in products like One User Avatar and Cover reflects the input-handling and form-validation demands of WordPress plugin architecture; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Onedesigns over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3860MEDIUM Cross-site scripting (XSS) vulnerability in the Cover WP theme before 1.6.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. | Sep 28, 2011 | 4.3 | 26 | NO | YES |
CVE-2021-24675MEDIUM The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is embed. As a result, attackers coul | Oct 18, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-24672MEDIUM The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allowing users with a role as low as Contributor to perform Store | Oct 18, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Onedesigns.
Media articles that mention a CVE ID that affects a product developed by Onedesigns — matched by CVE ID, not by vendor name.