Plainviewplugins develops a narrow set of WordPress plugins, primarily MyCryptoCheckout and Plainview Protect Passwords, focused on e-commerce and credential-management functionality. The observed vulnerability pattern centers on web-application input-handling and session-integrity weaknesses, specifically cross-site scripting and cross-site request forgery flaws typical of plugin-level exposure in WordPress environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plainviewplugins over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47664HIGH Cross-Site Request Forgery (CSRF) vulnerability in edward_plainview Plainview Protect Passwords.This issue affects Plainview Protect Passwords: from n/a through 1.4. | Nov 18, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-41693HIGH Cross-Site Request Forgery (CSRF) vulnerability in edward_plainview MyCryptoCheckout plugin <= 2.125 versions. | Oct 3, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-1546MEDIUM The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting | May 2, 2023 | 6.1 | 24 | NO | YES |
CVE-2023-47665MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in edward_plainview Plainview Protect Passwords plugin <= 1.4 versions. | Nov 14, 2023 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plainviewplugins.
Media articles that mention a CVE ID that affects a product developed by Plainviewplugins — matched by CVE ID, not by vendor name.