Quadlayers develops a focused set of WordPress plugins and e-commerce extensions, including Perfect Brands for WooCommerce, WP Social Chat, and WP Social Feed Gallery, that extend web-application functionality for small-business and publishing platforms. The observed vulnerability surface centers on web-application input handling and access control, with recurring weakness classes including cross-site scripting, cross-site request forgery, and improper access control that are characteristic of plugin-based WordPress extensions. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quadlayers over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-58686HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce perfect-woocommerce-brands allows SQ | Sep 22, 2025 | 8.5 | 27 | NO | NO |
CVE-2019-15779HIGH The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete. | Aug 29, 2019 | 8.8 | 26 | NO | NO |
CVE-2022-23982HIGH The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure. | Feb 18, 2022 | 7.5 | 24 | NO | NO |
CVE-2025-10144MEDIUM The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attribute of the `products` shortcode in all versions up to, and | Nov 24, 2025 | 6.5 | 22 | NO | NO |
CVE-2022-2361MEDIUM The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Sit | Aug 22, 2022 | 4.8 | 19 | NO | NO |
CVE-2024-39640MEDIUM Missing Authorization vulnerability in QuadLayers WP Social Feed Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Social Feed G | Nov 1, 2024 | 6.5 | 18 | NO | NO |
CVE-2022-23981MEDIUM The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4). | Feb 18, 2022 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quadlayers.
Media articles that mention a CVE ID that affects a product developed by Quadlayers — matched by CVE ID, not by vendor name.