Sumo develops a small set of WordPress plugins, including Google Analyticator and Social Share Boost, that extend analytics and social-sharing functionality for website publishers. The vulnerabilities affecting these plugins cluster around web-application input handling, with recurring issues in cross-site request forgery, cross-site scripting, and improper input validation—weakness classes typical of plugin-based content management extensions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sumo over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25033HIGH Cross-Site Request Forgery (CSRF) vulnerability in Sumo Social Share Boost plugin <= 4.5 versions. | Oct 6, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-4323HIGH The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injecti | Jan 23, 2023 | 7.2 | 24 | NO | NO |
CVE-2009-5158MEDIUM The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text. | Aug 22, 2019 | 6.1 | 22 | NO | NO |
CVE-2015-4697HIGH Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563. | Sep 7, 2017 | 8.8 | 22 | NO | NO |
CVE-2023-23688MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions. | May 15, 2023 | 5.4 | 20 | NO | NO |
CVE-2022-3425HIGH The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injecti | Jan 23, 2023 | 7.2 | 19 | NO | NO |
CVE-2023-25044MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions. | Sep 1, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sumo.
Media articles that mention a CVE ID that affects a product developed by Sumo — matched by CVE ID, not by vendor name.