Topdigitaltrends develops WordPress and page-builder plugins that extend content management and design capabilities, with its vulnerability profile centered on application-layer web-security defects including cross-site request forgery, cross-site scripting, and missing authorization checks. These weakness classes are typical of plugins that manipulate user input and generate dynamic page content in shared hosting environments. Current exploitation activity, severity levels, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Topdigitaltrends over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36798HIGH Cross-Site Request Forgery (CSRF) vulnerability in Topdigitaltrends Mega Addons For WPBakery Page Builder plugin <= 4.2.7 at WordPress. | Sep 23, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-4501MEDIUM The Mega Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the vc_saving_data function in versions up to, and including, 4.3.0. | Dec 14, 2022 | 6.5 | 22 | NO | NO |
CVE-2023-0280MEDIUM The Ultimate Carousel For Elementor WordPress plugin through 2.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block | May 8, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-0268MEDIUM The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post whe | May 8, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-0267MEDIUM The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/pos | May 8, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Topdigitaltrends.
Media articles that mention a CVE ID that affects a product developed by Topdigitaltrends — matched by CVE ID, not by vendor name.