Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Oxilab

First CVE: Jan 24, 2022Active for: 4 yearsTotal CVEs: 21
28.9
VTI Score
Low

Oxilab develops a focused line of WordPress plugins and Elementor add-ons centered on visual enhancement and content organization features such as image hover effects, accordions, tabs, and shortcode utilities. Despite a narrow product portfolio, these plugins achieve notable reach across WordPress installations, placing the vendor among the more prominent in the WordPress ecosystem. The vulnerability exposure recurs through input-validation weaknesses characteristic of web-form and page-generation contexts, particularly cross-site scripting and privilege-management issues that reflect the plugins' role in rendering user-controlled content and managing access to administrative features. Public exploit code has a moderate presence for vulnerabilities affecting this vendor, suggesting that defenders should prioritize patch deployment for exposed WordPress instances running these plugins. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Oxilab over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2022
4 years ago
Most Recent CVE
Jul 22, 2024
732 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-34487MEDIUM
Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.
Jul 21, 20225.329NOYES
CVE-2022-33198MEDIUM
Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.
Jul 21, 20225.329NOYES
CVE-2022-42459HIGH
Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.
Nov 18, 20227.224NONO
CVE-2022-38104HIGH
Auth. WordPress Options Change (siteurl, users_can_register, default_role, admin_email and new_admin_email) vulnerability in Biplob Adhikari's Accordions – Multiple Accordions or F
Oct 21, 20227.224NONO
CVE-2022-36375HIGH
Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress.
Jul 25, 20227.224NONO
CVE-2022-33970HIGH
Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress.
Jul 27, 20227.223NONO
CVE-2022-33969HIGH
Authenticated WordPress Options Change vulnerability in Biplob Adhikari's Flipbox plugin <= 2.6.0 at WordPress.
Jul 25, 20227.223NONO
CVE-2022-45831MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in biplob018 Image Hover Effects for Elementor with Lightbox and Flipbox plugin <= 2.8 versions.
Mar 28, 20236.122NONO
CVE-2021-25031MEDIUM
The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting i
Jan 24, 20226.122NONO
CVE-2022-4207MEDIUM
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4
Dec 13, 20225.421NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
76%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (33.3%)
Unknown0 (0.0%)
Required14 (66.7%)
Privileges Required
Low6 (28.6%)
High11 (52.4%)
None4 (19.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
9.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Oxilab.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Oxilab — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Oxilab's Products

View all 3 CNAs →

Top CWEs