Private Messages Project maintains a focused messaging application where its disclosed vulnerabilities center on web-layer input-handling and request-validation weaknesses, specifically cross-site scripting and cross-site request forgery. Current severity, exploitation status, and exposure details are shown in the live statistics panel alongside this summary.
The number and severity of CVEs published that impact products developed by Private Messages Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29442MEDIUM Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress <= 2.1.10 at WordPress. | Jun 15, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-29441MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Private Messages For WordPress plugin <= 2.1.10 at WordPress allows attackers to send messages. | Jun 15, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Private Messages Project.
Media articles that mention a CVE ID that affects a product developed by Private Messages Project — matched by CVE ID, not by vendor name.