Rymera develops a focused suite of e-commerce and merchandising plugins, including Wholesale Suite, Advanced Coupons, and Auto Refresh Single Page, where disclosures concentrate on web application input-handling and authorization issues such as cross-site request forgery, cross-site scripting, and improper neutralization of untrusted data, alongside deserialization risks. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rymera over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1731HIGH The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1 via deserialization of untrusted input from the ar | Mar 5, 2024 | 8.8 | 27 | NO | NO |
CVE-2022-34344HIGH Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More.Thi | Jan 8, 2024 | 8.8 | 23 | NO | NO |
CVE-2022-41640MEDIUM Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Rymera Web Co Wholesale Suite plugin <= 2.1.5 versions. | May 9, 2023 | 5.4 | 20 | NO | NO |
CVE-2022-43481MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Advanced Coupons for WooCommerce Coupons plugin <= 4.5 on WordPress leading to notice dismissal. | Nov 8, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rymera.
Media articles that mention a CVE ID that affects a product developed by Rymera — matched by CVE ID, not by vendor name.