Sayandatta develops WordPress plugins, notably Simple Posts Ticker and WP Last Modified Info, with a durable vulnerability signal centered on cross-site scripting flaws arising from improper input neutralization in web page generation. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sayandatta over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-52756HIGH Improper Control of Generation of Code ('Code Injection') vulnerability in Sayan Datta WP Last Modified Info wp-last-modified-info allows Remote Code Inclusion.This issue affects W | Oct 22, 2025 | 7.4 | 23 | NO | NO |
CVE-2025-62968MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sayan Datta WP Last Modified Info wp-last-modified-info allows Stored XSS.This | Oct 27, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-6864MEDIUM The WP Last Modified Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘template’ attribute of the lmt-post-modified-info shortcode in all versions up | Aug 20, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-4646MEDIUM The Simple Posts Ticker WordPress plugin before 1.1.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode i | Oct 16, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-4725MEDIUM The Simple Posts Ticker WordPress plugin before 1.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cros | Oct 16, 2023 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sayandatta.
Media articles that mention a CVE ID that affects a product developed by Sayandatta — matched by CVE ID, not by vendor name.