Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Smackcoders

First CVE: Nov 5, 2013Active for: 13 yearsTotal CVEs: 26
41.2
VTI Score
High

Smackcoders develops a focused suite of WordPress and data-integration plugins, including CSV and XML import/export utilities and integration tools for third-party services, with moderate representation in the vulnerability landscape. Its disclosures cluster around common web-application and plugin-oriented weakness classes: cross-site scripting, cross-site request forgery, SQL injection, improper authorization, and exposure of sensitive information, reflecting the input-handling and access-control demands of data-processing and integration layers. A meaningful share of the vendor's vulnerabilities reach serious severity, typical for plugins that operate within the WordPress ecosystem and handle user-supplied content or administrative functions. Defenders tracking WordPress deployments should monitor this vendor's release cycle, particularly for instances where these plugins process sensitive data or have administrative scope. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Smackcoders over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 5, 2013
12 years ago
Most Recent CVE
Dec 2, 2025
234 days ago

Products(9 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-43965CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders SendGrid for WordPress allows SQL Injection.This issue affects Sen
Aug 29, 20249.842NOYES
CVE-2016-11000CRITICAL
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
Sep 20, 20199.831NONO
CVE-2025-2332CRITICAL
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of
Mar 27, 20259.828NONO
CVE-2022-3860HIGH
The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injec
Jan 2, 20238.828NONO
CVE-2023-4142HIGH
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' parameter. This allows authenticat
Aug 4, 20238.827NONO
CVE-2023-4141HIGH
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' parameter. This allows authenticat
Aug 4, 20238.826NONO
CVE-2023-4140HIGH
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient restriction on the 'get_header_v
Aug 4, 20238.826NONO
CVE-2018-20967HIGH
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
Aug 14, 20198.826NONO
CVE-2015-10125HIGH
A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site r
Oct 5, 20238.825NONO
CVE-2018-20968HIGH
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
Aug 14, 20198.825NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
38%
50%
12%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (92.3%)
Unknown2 (7.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (88.5%)
High1 (3.8%)
Unknown2 (7.7%)
User Interaction
None16 (61.5%)
Unknown2 (7.7%)
Required8 (30.8%)
Privileges Required
Low7 (26.9%)
High3 (11.5%)
None14 (53.8%)
Unknown2 (7.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.8% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Smackcoders.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Smackcoders — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Smackcoders's Products

View all 5 CNAs →

Top CWEs