Plugin maintains a modestly represented portfolio centered on a small set of web-facing applications such as YourChannel and Waiting, where disclosures cluster around application-layer input-handling and authorization issues including cross-site scripting, SQL injection, cross-site request forgery, and missing authorization controls. These are characteristic of web application architectures and merit standard application-security review practices within development workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plugin over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28659HIGH The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_sav | Mar 22, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-1865MEDIUM The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when resetting plugin settings via the yrc_nuke GET parameter in | Apr 5, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-0282MEDIUM The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting | Feb 6, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-1868MEDIUM The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when clearing the plugin cache via the yrc_clear_cache GET paramet | Apr 5, 2023 | 5.3 | 19 | NO | NO |
CVE-2022-4833MEDIUM The YourChannel: Everything you want in a YouTube plugin WordPress plugin before 1.2.3 does not validate and escape some of its shortcode attributes before outputting them back in | Feb 6, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-4000MEDIUM The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.2. This is due to missing or incorrect nonc | Aug 31, 2023 | 4.3 | 18 | NO | NO |
CVE-2023-1869MEDIUM The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.5 due to insufficient input sanitization | Apr 5, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-1871MEDIUM The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4. This is due to missing or incorrect nonce validation on th | Apr 5, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-1870MEDIUM The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4. This is due to missing or incorrect nonce validation on th | Apr 5, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-1867MEDIUM The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4. This is due to missing or incorrect nonce validation on th | Apr 5, 2023 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plugin.
Media articles that mention a CVE ID that affects a product developed by Plugin — matched by CVE ID, not by vendor name.