Renzojohnson's vulnerability footprint centers on WordPress extensions and plugins such as Blocks, Contact Form 7 Campaign Monitor Extension, and Contact Form 7 Extension for Mailchimp, which serve site-building and email-integration functions. The observed weakness classes—cross-site scripting, missing authorization, and server-side request forgery—reflect the input-handling and access-control challenges endemic to WordPress plugin development. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Renzojohnson over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-44019CRITICAL Missing Authorization vulnerability in Renzo Johnson Contact Form 7 Campaign Monitor Extension contact-form-7-campaign-monitor-extension.This issue affects Contact Form 7 Campaign | Nov 1, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-22134MEDIUM Server-Side Request Forgery (SSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affects Contact Form 7 Extension For Mailchimp: from n/a through | Jan 24, 2024 | 6.5 | 19 | NO | NO |
CVE-2023-44262MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Renzo Johnson Blocks plugin <= 1.6.41 versions. | Oct 2, 2023 | 4.8 | 17 | NO | NO |
CVE-2024-33677MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affects Contact Form 7 Extension For Mailchimp: from n/a through | Apr 26, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Renzojohnson.
Media articles that mention a CVE ID that affects a product developed by Renzojohnson — matched by CVE ID, not by vendor name.