Pluginops develops a focused suite of landing-page and form-integration tools, with the durable signal centered on web-application input-handling issues such as cross-site scripting and open redirects. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pluginops over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57337HIGH Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions. | Jun 29, 2026 | 7.1 | 33 | NO | NO |
CVE-2021-25067MEDIUM The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page. | Jan 17, 2022 | 5.4 | 30 | NO | YES |
CVE-2024-34752HIGH Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Reflected XSS.This issue affects | May 17, 2024 | 7.1 | 23 | NO | NO |
CVE-2024-43345HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginOps Landing Page Builder allows PHP Local File Inclusion.This issue affects La | Aug 19, 2024 | 7.5 | 22 | NO | NO |
CVE-2022-4718MEDIUM The Landing Page Builder WordPress plugin before 1.4.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow us | Jan 23, 2023 | 5.4 | 21 | NO | NO |
CVE-2026-24620MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder page-builder-add allows Stored XSS.This issue a | Jan 23, 2026 | 5.9 | 19 | NO | NO |
CVE-2023-48325MEDIUM URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages.This issue aff | Dec 7, 2023 | 6.1 | 19 | NO | NO |
CVE-2024-30452MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Stored XSS.This issue affects Landing Pa | Mar 29, 2024 | 5.9 | 18 | NO | NO |
CVE-2023-33328MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps MailChimp Subscribe Form plugin <= 4.0.9.1 versions. | May 28, 2023 | 4.8 | 17 | NO | NO |
CVE-2023-40675MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps Landing Page Builder plugin <= 1.5.1.2 versions. | Sep 27, 2023 | 4.8 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pluginops.
Media articles that mention a CVE ID that affects a product developed by Pluginops — matched by CVE ID, not by vendor name.