Shanebp maintains BP Email Assign Templates, a plugin-based email management extension, with its vulnerability profile centered on authorization and input-handling weaknesses including authorization bypass through user-controlled keys and cross-site scripting in dynamic web content generation. Current severity, exploitation, and exposure counts are shown in the live-stats panel alongside this summary.
The number and severity of CVEs published that impact products developed by Shanebp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-24631HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Reflected X | Feb 3, 2025 | 7.1 | 19 | NO | NO |
CVE-2024-12441MEDIUM The BP Email Assign Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.5 due to insuffi | Dec 12, 2024 | 6.1 | 18 | NO | NO |
CVE-2025-28875MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Stored XSS. | Mar 11, 2025 | 4.8 | 16 | NO | NO |
CVE-2025-28874MEDIUM Authorization Bypass Through User-Controlled Key vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Exploiting Incorrectly Configured Access Contro | Mar 11, 2025 | 4.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shanebp.
Media articles that mention a CVE ID that affects a product developed by Shanebp — matched by CVE ID, not by vendor name.