The Vertical Scroll Recent Post Project maintains a narrowly scoped WordPress plugin focused on displaying recent posts with vertical scrolling functionality. Observed vulnerabilities center on cross-site scripting arising from improper input neutralization during page generation, a class common to web-facing plugins handling user-supplied content.
The number and severity of CVEs published that impact products developed by Vertical Scroll Recent Post Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23862MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Vertical scroll recent post plugin <= 14.0 versions. | May 9, 2023 | 5.4 | 20 | NO | NO |
CVE-2022-1171MEDIUM The Vertical scroll recent post WordPress plugin before 14.0 does not sanitise and escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site S | May 9, 2022 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vertical Scroll Recent Post Project.
Media articles that mention a CVE ID that affects a product developed by Vertical Scroll Recent Post Project — matched by CVE ID, not by vendor name.