The Ultimate Nofollow Project maintains a narrowly scoped WordPress plugin focused on link-attribute management, with its vulnerability profile centered on the core product itself. The durable signal reflects application-layer input-handling weaknesses, specifically cross-site scripting issues in web page generation, which are characteristic of plugins that process and output user-controlled content. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ultimate Nofollow Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24817MEDIUM The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, allowing users with a role as low as contributor to perform | Dec 13, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ultimate Nofollow Project.
Media articles that mention a CVE ID that affects a product developed by Ultimate Nofollow Project — matched by CVE ID, not by vendor name.