Softlabbd's vulnerability profile centers on a small suite of WordPress-related plugins and browser extensions, including a radio player, Google Drive integration tool, and form-field enhancement products deployed across modestly sized WordPress installations. Vulnerabilities affecting this vendor skew toward serious outcomes and recur through web-application weakness classes including missing authorization, cross-site scripting, cross-site request forgery, improper authentication, and open-redirect flaws that are characteristic of plugin-layer access and input handling. Defenders should prioritize keeping these plugins updated and restrict administrative access; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Softlabbd over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-35661CRITICAL Missing Authorization vulnerability in SoftLab Upload Fields for WPForms.This issue affects Upload Fields for WPForms: from n/a through 1.0.2. | Jun 9, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-35670CRITICAL Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.93. | Jun 4, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-49769HIGH Cross-Site Request Forgery (CSRF) vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.4. | Dec 17, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-52177MEDIUM Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.3. | Jun 12, 2024 | 6.3 | 18 | NO | NO |
CVE-2024-34753MEDIUM Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | Jun 11, 2024 | 5.3 | 18 | NO | NO |
CVE-2023-47548MEDIUM URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google | Dec 7, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-4027MEDIUM The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_settings function in versions up to, and in | Aug 17, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-29811MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftLab Radio Player allows Stored XSS.This issue affects Radio Player: from n | Mar 27, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-8267MEDIUM The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute wit | Sep 25, 2024 | 5.4 | 16 | NO | NO |
CVE-2023-4024MEDIUM The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions up to, and incl | Aug 17, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Softlabbd.
Media articles that mention a CVE ID that affects a product developed by Softlabbd — matched by CVE ID, not by vendor name.