Pluginsandsnippets maintains a focused product portfolio centered on the Simple Page Access Restriction plugin, with vulnerabilities clustering around access-control boundaries and cross-site request forgery defenses typical of web application plugins. The recurring weakness classes reflect common implementation gaps in permission enforcement and CSRF token validation that can arise in plugin-based extensibility architectures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pluginsandsnippets over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-5142MEDIUM The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce valid | May 30, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-58202MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Plugins and Snippets Simple Page Access Restriction simple-page-access-restriction allows Cross Site Request Forgery.This issue a | Aug 27, 2025 | 4.3 | 18 | NO | NO |
CVE-2024-11295MEDIUM The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 via the WordPress core search f | Dec 18, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-0965MEDIUM The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it | Feb 8, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pluginsandsnippets.
Media articles that mention a CVE ID that affects a product developed by Pluginsandsnippets — matched by CVE ID, not by vendor name.