Rednao develops a focused portfolio of WordPress plugins and donation-management tools, including Smart Forms, Smart Donations, and WooCommerce PDF Invoice Builder, which serve small-to-medium business and nonprofit segments. The vendor's vulnerability profile concentrates on web-application input-handling and authorization issues endemic to plugin-based WordPress extensions, with recurring weakness classes including cross-site scripting, cross-site request forgery, SQL injection, and missing or improper authorization controls. These classes reflect the challenges of securing dynamically generated content and form processing in plugin architectures where privilege enforcement and input sanitization are critical. Defenders deploying Rednao plugins should prioritize timely updates and review access controls around administrative and donation-processing functions; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rednao over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38475HIGH Missing Authorization vulnerability in RedNao Donations Made Easy – Smart Donations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Donat | Dec 13, 2024 | 8.8 | 28 | NO | NO |
CVE-2023-40207CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedNao Donations Made Easy – Smart Donations allows SQL Injection.This issue a | Nov 6, 2023 | 9.8 | 28 | NO | NO |
CVE-2019-5924HIGH Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted pag | Mar 12, 2019 | 8.8 | 27 | NO | NO |
CVE-2023-49856HIGH Missing Authorization vulnerability in EDGARROJAS Smart Forms smart-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Forms: fr | Dec 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-47551HIGH Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12. | Nov 18, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-3677HIGH The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in versions up to, and including, 1.2.89 due to insufficient escapi | Aug 31, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-51486HIGH Cross-Site Request Forgery (CSRF) vulnerability in RedNao WooCommerce PDF Invoice Builder.This issue affects WooCommerce PDF Invoice Builder: from n/a through 1.2.101. | Mar 16, 2024 | 8.8 | 23 | NO | NO |
CVE-2022-0163MEDIUM The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, | Mar 7, 2022 | 6.5 | 23 | NO | NO |
CVE-2024-1307MEDIUM The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a subscriber to call them and perf | Apr 15, 2024 | 6.5 | 22 | NO | NO |
CVE-2023-7203MEDIUM The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow users with a role as low as subscriber to call them and perfor | Feb 27, 2024 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rednao.
Media articles that mention a CVE ID that affects a product developed by Rednao — matched by CVE ID, not by vendor name.