Smackcoders develops a focused suite of WordPress and data-integration plugins, including CSV and XML import/export utilities and integration tools for third-party services, with moderate representation in the vulnerability landscape. Its disclosures cluster around common web-application and plugin-oriented weakness classes: cross-site scripting, cross-site request forgery, SQL injection, improper authorization, and exposure of sensitive information, reflecting the input-handling and access-control demands of data-processing and integration layers. A meaningful share of the vendor's vulnerabilities reach serious severity, typical for plugins that operate within the WordPress ecosystem and handle user-supplied content or administrative functions. Defenders tracking WordPress deployments should monitor this vendor's release cycle, particularly for instances where these plugins process sensitive data or have administrative scope. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smackcoders over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43965CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders SendGrid for WordPress allows SQL Injection.This issue affects Sen | Aug 29, 2024 | 9.8 | 42 | NO | YES |
CVE-2016-11000CRITICAL The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter. | Sep 20, 2019 | 9.8 | 31 | NO | NO |
CVE-2025-2332CRITICAL The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of | Mar 27, 2025 | 9.8 | 28 | NO | NO |
CVE-2022-3860HIGH The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injec | Jan 2, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-4142HIGH The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' parameter. This allows authenticat | Aug 4, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-4141HIGH The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' parameter. This allows authenticat | Aug 4, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-4140HIGH The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient restriction on the 'get_header_v | Aug 4, 2023 | 8.8 | 26 | NO | NO |
CVE-2018-20967HIGH The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF. | Aug 14, 2019 | 8.8 | 26 | NO | NO |
CVE-2015-10125HIGH A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site r | Oct 5, 2023 | 8.8 | 25 | NO | NO |
CVE-2018-20968HIGH The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF. | Aug 14, 2019 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smackcoders.
Media articles that mention a CVE ID that affects a product developed by Smackcoders — matched by CVE ID, not by vendor name.