Onetarek maintains a focused WordPress plugin product portfolio centered on the WP Logs Book logging and auditing plugin, with a durable vulnerability profile anchored in web-application input-handling and request-validation defects. The observed weakness classes—cross-site scripting and cross-site request forgery—reflect common plugin-development patterns around form handling and user-supplied content rendering within the WordPress ecosystem. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Onetarek over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4474MEDIUM The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via | Jun 21, 2024 | 4.3 | 17 | NO | NO |
CVE-2024-4477MEDIUM The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin dashboard, leading to an Unauthenticated S | Jun 21, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-4475MEDIUM The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check when clearing logs, which could allow attackers to make a logged in admin clear the logs them via a CSRF at | Jun 21, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Onetarek.
Media articles that mention a CVE ID that affects a product developed by Onetarek — matched by CVE ID, not by vendor name.