Technowich's vulnerability profile centers on WP ULike, a WordPress plugin that extends core functionality around user engagement and social interactions. The recurring exposure reflects the typical vulnerabilities of WordPress plugin development: cross-site scripting flaws in user-facing input handling and time-of-check time-of-use race conditions that arise from concurrent access patterns in web application state management. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Technowich over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7879MEDIUM The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scriptin | Nov 6, 2024 | 4.8 | 17 | NO | NO |
Unauth. Race Condition vulnerability in WP ULike Plugin <= 4.6.4 on WordPress allows attackers to increase/decrease rating scores. | Nov 30, 2022 | 3.7 | 17 | NO | NO |
CVE-2024-7878MEDIUM The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scr | Sep 25, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-6094MEDIUM The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scr | Jul 24, 2024 | 4.8 | 16 | NO | NO |
CVE-2023-45640MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TechnoWich WP ULike – Most Advanced WordPress Marketing Toolkit plugin <= 4.6.8 versions. | Oct 25, 2023 | 5.4 | 16 | NO | NO |
CVE-2024-12770MEDIUM The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scr | May 15, 2025 | 4.8 | 15 | NO | NO |
The WP ULike WordPress plugin before 4.7.2.1 does not properly sanitize user display names when rendering on a public page. | Sep 6, 2024 | 3.5 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Technowich.
Media articles that mention a CVE ID that affects a product developed by Technowich — matched by CVE ID, not by vendor name.