Richplugins develops a focused WordPress plugin for Google Reviews integration, with a narrow but established product footprint. The vulnerability pattern centers on application-layer input-handling issues, chiefly cross-site scripting and SQL injection, which are typical of web-facing plugin code that must parse and display user-supplied or third-party content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Richplugins over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44580HIGH SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions. | Mar 15, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-45369MEDIUM Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress. | Nov 18, 2022 | 4.3 | 18 | NO | NO |
CVE-2023-6884MEDIUM This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization a | Feb 5, 2024 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Richplugins.
Media articles that mention a CVE ID that affects a product developed by Richplugins — matched by CVE ID, not by vendor name.