Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Plugin Planet

First CVE: Sep 20, 2019Active for: 7 yearsTotal CVEs: 44

Plugin Planet develops a modest portfolio of WordPress plugins focused on user engagement, content management, and site customization features. The vendor's disclosures center on a small set of recurrent plugins including User Submitted Posts, Simple AJAX Chat, Dashboard Widget Suite, Prismatic, and Simple Download Counter. While the vendor does carry a meaningful vulnerability footprint, the exposure does not concentrate in any single dominant weakness class, and the products involved are typical of the WordPress plugin ecosystem's broad, distributed attack surface. Defenders tracking WordPress deployments should monitor this vendor's advisories as part of a broader plugin-security discipline, though the exposure itself does not demand specialized isolation tactics; live severity, exploitation, and product-exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Plugin Planet over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 20, 2019
6 years ago
Most Recent CVE
Apr 22, 2025
458 days ago

Products(9 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-27849HIGH
Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115
Apr 15, 20227.536NOYES
CVE-2022-1165CRITICAL
The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, whi
Apr 4, 20229.129NONO
CVE-2021-24409MEDIUM
The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which
Jul 12, 20216.129NOYES
CVE-2023-45603CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted
Dec 20, 20239.828NONO
CVE-2019-25138CRITICAL
The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and in
Jun 7, 20239.828NONO
CVE-2022-25601MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).
Mar 11, 20226.122NONO
CVE-2024-1983HIGH
The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users.
Mar 20, 20247.121NONO
CVE-2023-4308MEDIUM
The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-content’ parameter in versions up to, and including, 20230809 due
Aug 15, 20235.420NONO
CVE-2023-4838MEDIUM
The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.6 due to insufficient
Sep 9, 20235.419NONO
CVE-2023-4779MEDIUM
The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery] shortcode in versions up to, and including, 20230811 due t
Sep 6, 20235.419NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
77%
9%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (18.2%)
Unknown0 (0.0%)
Required18 (81.8%)
Privileges Required
Low8 (36.4%)
High3 (13.6%)
None11 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
9.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Plugin Planet.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Plugin Planet — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Plugin Planet's Products

View all 4 CNAs →

Top CWEs