Redefiningtheweb develops a narrow portfolio of WordPress-oriented products—notably the Affiliate Pro plugin and PDF Generator Addon for Elementor—centered on e-commerce and content-generation functionality. The durable signal centers on authentication and input-handling weaknesses, including authentication-bypass flaws via alternate channels, cross-site scripting, and missing authentication controls on critical functions, which are characteristic of plugin-layer exposure in WordPress ecosystems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Redefiningtheweb over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9289CRITICAL The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_lo | Oct 1, 2024 | 9.8 | 29 | NO | NO |
CVE-2025-31850MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Page Builder pdf-generator- | Apr 1, 2025 | 6.5 | 21 | NO | NO |
CVE-2025-24569HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Page Builder pdf-generator-addon- | Feb 3, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-50449MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Page Builder pdf-generator- | Oct 28, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Redefiningtheweb.
Media articles that mention a CVE ID that affects a product developed by Redefiningtheweb — matched by CVE ID, not by vendor name.