Plugin Planet develops a modest portfolio of WordPress plugins focused on user engagement, content management, and site customization features. The vendor's disclosures center on a small set of recurrent plugins including User Submitted Posts, Simple AJAX Chat, Dashboard Widget Suite, Prismatic, and Simple Download Counter. While the vendor does carry a meaningful vulnerability footprint, the exposure does not concentrate in any single dominant weakness class, and the products involved are typical of the WordPress plugin ecosystem's broad, distributed attack surface. Defenders tracking WordPress deployments should monitor this vendor's advisories as part of a broader plugin-security discipline, though the exposure itself does not demand specialized isolation tactics; live severity, exploitation, and product-exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plugin Planet over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27849HIGH Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115 | Apr 15, 2022 | 7.5 | 36 | NO | YES |
CVE-2022-1165CRITICAL The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, whi | Apr 4, 2022 | 9.1 | 29 | NO | NO |
CVE-2021-24409MEDIUM The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which | Jul 12, 2021 | 6.1 | 29 | NO | YES |
CVE-2023-45603CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted | Dec 20, 2023 | 9.8 | 28 | NO | NO |
CVE-2019-25138CRITICAL The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and in | Jun 7, 2023 | 9.8 | 28 | NO | NO |
CVE-2022-25601MEDIUM Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4). | Mar 11, 2022 | 6.1 | 22 | NO | NO |
CVE-2024-1983HIGH The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users. | Mar 20, 2024 | 7.1 | 21 | NO | NO |
CVE-2023-4308MEDIUM The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-content’ parameter in versions up to, and including, 20230809 due | Aug 15, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-4838MEDIUM The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.6 due to insufficient | Sep 9, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-4779MEDIUM The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery] shortcode in versions up to, and including, 20230811 due t | Sep 6, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plugin Planet.
Media articles that mention a CVE ID that affects a product developed by Plugin Planet — matched by CVE ID, not by vendor name.