Palmspark operates a narrowly scoped WordPress plugin portfolio centered on the WP User Control product, which manages user authentication and access workflows within WordPress deployments. The vendor's vulnerability footprint reflects the authentication-handling role of its plugin, with observed disclosures clustering around unverified password-change workflows that can allow account takeover or privilege escalation. Live exploitation status, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Palmspark over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4915MEDIUM The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.5.3. This is due to the plugin using native password reset | Sep 13, 2023 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Palmspark.
Media articles that mention a CVE ID that affects a product developed by Palmspark — matched by CVE ID, not by vendor name.