Techearty develops WordPress plugins focused on content presentation, including carousel sliders and gallery components, along with accordion functionality—plugins with niche but persistent adoption across self-hosted WordPress sites. The vulnerabilities affecting this vendor recur through cross-site scripting weaknesses in client-side content rendering, a characteristic risk in plugins that dynamically generate and output user-supplied or admin-configured content without adequate input sanitization. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Techearty over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4482MEDIUM The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, wh | Jan 16, 2023 | 5.4 | 21 | NO | NO |
CVE-2022-4487MEDIUM The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with | Jan 16, 2023 | 5.4 | 20 | NO | NO |
CVE-2021-24576MEDIUM The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion. | Oct 11, 2021 | 5.4 | 20 | NO | NO |
CVE-2024-1363MEDIUM The Easy Accordion – Best Accordion FAQ Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordion_content_source' attribute in all v | Mar 13, 2024 | 5.4 | 17 | NO | NO |
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin | May 15, 2025 | 3.5 | 14 | NO | NO |
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin | Feb 21, 2025 | 3.5 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Techearty.
Media articles that mention a CVE ID that affects a product developed by Techearty — matched by CVE ID, not by vendor name.