Undolog develops a small set of WordPress plugins including CleanFix and WP Bannerize Pro, where reported vulnerabilities center on web-application input-handling issues such as cross-site request forgery and cross-site scripting. These are characteristic weaknesses in plugin-based content management, reflecting the intersection of user-supplied data and administrative interfaces. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Undolog over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2109HIGH WordPress plugin wp-cleanfix has Remote Code Execution | Feb 10, 2020 | 8.8 | 26 | NO | NO |
CVE-2013-2108MEDIUM WordPress WP Cleanfix Plugin 2.4.4 has CSRF | Feb 10, 2020 | 5.4 | 24 | NO | YES |
CVE-2023-41663MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Giovambattista Fazioli WP Bannerize Pro plugin <= 1.6.9 versions. | Sep 29, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Undolog.
Media articles that mention a CVE ID that affects a product developed by Undolog — matched by CVE ID, not by vendor name.