Really Simple Plugins develops a focused line of WordPress plugins addressing compliance, content management, and security functions, with a modest but durable vulnerability footprint concentrated across products such as Complianz, Recipe Maker for Your Food Blog, and Really Simple Security. The vulnerabilities observed across this vendor's portfolio reflect the input-handling and access-control challenges characteristic of web-based plugin architecture, though the specific weakness patterns have not clustered into a dominant class. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Really Simple Plugins over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-10924CRITICAL The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user c | Nov 15, 2024 | 9.8 | 91 | NO | YES |
CVE-2022-3494HIGH The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL | Nov 7, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-34030HIGH Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Request Forgery.This issue affects Com | Nov 30, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-33333HIGH Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Scripting (XSS).This issue affects Com | Nov 30, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-35089HIGH Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions. | Jul 17, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-52180HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes.This is | Dec 31, 2023 | 8.1 | 22 | NO | NO |
CVE-2022-0193MEDIUM The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting | Feb 14, 2022 | 6.1 | 22 | NO | NO |
CVE-2023-1069MEDIUM The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back | Mar 27, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-31076MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.6 versions. | Aug 17, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-6498MEDIUM The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insuf | Jan 4, 2024 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Really Simple Plugins.
Media articles that mention a CVE ID that affects a product developed by Really Simple Plugins — matched by CVE ID, not by vendor name.