Peepso is a social networking and community plugin that integrates into WordPress, presenting an attack surface centered on web application input handling and session management. Vulnerabilities in the product recur through weakness classes including cross-site scripting, cross-site request forgery, improper privilege controls, and sensitive information exposure, reflecting the complexity of managing user interaction and data visibility in a plugin-based social platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Peepso over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25967HIGH Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo plugin <= 6.0.2.0 versions. | May 3, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-41633HIGH Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin <= 6.0.2.0 versions. | Apr 4, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-32092HIGH Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin <= 6.0.9.0 versions. | Nov 9, 2023 | 8.8 | 25 | NO | NO |
CVE-2016-10968HIGH The peepso-core plugin before 1.6.1 for WordPress has PeepSoProfilePreferencesAjax->save() privilege escalation. | Sep 16, 2019 | 8.8 | 25 | NO | NO |
CVE-2023-39925HIGH Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Download Community by PeepSo plugin <= 6.1.6.0 versions. | Nov 22, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-0187MEDIUM The Community by PeepSo WordPress plugin before 6.3.1.2 does not sanitise and escape various parameters and generated URLs before outputting them back attributes, leading to a Refl | Jan 16, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-22158MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Pr | Jan 31, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-48746MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Pr | Nov 30, 2023 | 6.1 | 17 | NO | NO |
CVE-2023-47850MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Pr | Nov 30, 2023 | 5.4 | 17 | NO | NO |
CVE-2024-7426MEDIUM The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6 | Sep 25, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Peepso.
Media articles that mention a CVE ID that affects a product developed by Peepso — matched by CVE ID, not by vendor name.