Sprintexperts offers WordPress plugin functionality through its Extra Fields product, presenting a modest web-application attack surface centered on user-facing form and data-handling features. The observed vulnerability signal reflects input-sanitization gaps typical of this class, with cross-site scripting emerging as the recurring weakness across the vendor's disclosures. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sprintexperts over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13632HIGH The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which | Feb 26, 2025 | 7.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sprintexperts.
Media articles that mention a CVE ID that affects a product developed by Sprintexperts — matched by CVE ID, not by vendor name.