Plechevandrey's vulnerability profile centers on WP Recall, a WordPress-focused plugin that presents a modestly represented but prominent footprint in the web-application landscape. Vulnerabilities affecting this product skew toward serious outcomes and frequently acquire public exploit code, clustering around input-validation and authorization weaknesses—cross-site scripting, SQL injection, missing authorization checks, and sensitive-information exposure—that are characteristic of web plugins handling user input and database queries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plechevandrey over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1323CRITICAL The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26. | Mar 8, 2025 | 9.8 | 43 | NO | YES |
CVE-2024-32709CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26. | Apr 24, 2024 | 9.3 | 38 | NO | YES |
CVE-2024-8292CRITICAL The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. Th | Sep 6, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-32710HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26. | Apr 24, 2024 | 8.5 | 23 | NO | NO |
CVE-2025-1325MEDIUM The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execution due to a missing capability check on the 'rcl_preview_pos | Mar 8, 2025 | 6.3 | 19 | NO | NO |
CVE-2025-1324MEDIUM The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'public-form' shortcode in all versions up | Mar 8, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-1175MEDIUM The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_payment' fun | Jun 6, 2024 | 5.3 | 18 | NO | NO |
CVE-2025-1322MEDIUM The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 16.26.10 via the 'feed' shor | Mar 8, 2025 | 4.3 | 17 | NO | NO |
CVE-2024-35657MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.6. | Jun 8, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-9770MEDIUM The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | Mar 25, 2025 | 4.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plechevandrey.
Media articles that mention a CVE ID that affects a product developed by Plechevandrey — matched by CVE ID, not by vendor name.