Oxilab develops a focused line of WordPress plugins and Elementor add-ons centered on visual enhancement and content organization features such as image hover effects, accordions, tabs, and shortcode utilities. Despite a narrow product portfolio, these plugins achieve notable reach across WordPress installations, placing the vendor among the more prominent in the WordPress ecosystem. The vulnerability exposure recurs through input-validation weaknesses characteristic of web-form and page-generation contexts, particularly cross-site scripting and privilege-management issues that reflect the plugins' role in rendering user-controlled content and managing access to administrative features. Public exploit code has a moderate presence for vulnerabilities affecting this vendor, suggesting that defenders should prioritize patch deployment for exposed WordPress instances running these plugins. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oxilab over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34487MEDIUM Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress. | Jul 21, 2022 | 5.3 | 29 | NO | YES |
CVE-2022-33198MEDIUM Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress. | Jul 21, 2022 | 5.3 | 29 | NO | YES |
CVE-2022-42459HIGH Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress. | Nov 18, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-38104HIGH Auth. WordPress Options Change (siteurl, users_can_register, default_role, admin_email and new_admin_email) vulnerability in Biplob Adhikari's Accordions – Multiple Accordions or F | Oct 21, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-36375HIGH Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress. | Jul 25, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-33970HIGH Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress. | Jul 27, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-33969HIGH Authenticated WordPress Options Change vulnerability in Biplob Adhikari's Flipbox plugin <= 2.6.0 at WordPress. | Jul 25, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-45831MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in biplob018 Image Hover Effects for Elementor with Lightbox and Flipbox plugin <= 2.8 versions. | Mar 28, 2023 | 6.1 | 22 | NO | NO |
CVE-2021-25031MEDIUM The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting i | Jan 24, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-4207MEDIUM The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4 | Dec 13, 2022 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oxilab.
Media articles that mention a CVE ID that affects a product developed by Oxilab — matched by CVE ID, not by vendor name.