Vektor Inc develops a focused suite of WordPress plugins and page-building tools, including products such as VK All in One Expansion Unit, VK Blocks, VK Block Patterns, and VK Filter Search that extend WordPress functionality for content management and site customization. The vendor's vulnerability profile reflects the attack surface typical of widely installed WordPress extensions—plugins that operate within the WordPress ecosystem and interface with user input, content storage, and site administration. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vektor Inc over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27926MEDIUM Cross-site scripting vulnerability in Profile setting function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary sc | May 23, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-0937MEDIUM The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead | Mar 20, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-0230MEDIUM The VK All in One Expansion Unit WordPress plugin before 9.86.0.0 does not validate and escape some of its block options before outputting them back in a page/post where the block | Feb 27, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-28367MEDIUM Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script. | May 23, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-27925MEDIUM Cross-site scripting vulnerability in Post function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arb | May 23, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-27923MEDIUM Cross-site scripting vulnerability in Tag edit function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an | May 23, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-2093MEDIUM The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.95.0.1 via social meta tags. This make | Apr 9, 2024 | 5.3 | 18 | NO | NO |
CVE-2023-5705MEDIUM The VK Filter Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk_filter_search' shortcode in all versions up to, and including, 2.3.1 due | Oct 27, 2023 | 5.4 | 18 | NO | NO |
CVE-2024-52268MEDIUM Cross-site scripting vulnerability exists in VK All in One Expansion Unit versions prior to 9.100.1.0. If this vulnerability is exploited, an arbitrary script may be executed on th | Nov 13, 2024 | 4.8 | 17 | NO | NO |
CVE-2024-37956MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vektor,Inc. VK All in One Expansion Unit allows Stored XSS.This issue a | Jul 20, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vektor Inc.
Media articles that mention a CVE ID that affects a product developed by Vektor Inc — matched by CVE ID, not by vendor name.