Verygoodplugins operates a modest portfolio of WordPress plugins, including WP Fusion and Fatal Error Notify, where the durable signal centers on application-layer input and request-handling weaknesses such as cross-site scripting and cross-site request forgery. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Verygoodplugins over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34660MEDIUM The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in the ~/includes/admin/logging/class-log-table-list.php file | Aug 9, 2021 | 6.1 | 21 | NO | NO |
CVE-2023-7202MEDIUM The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such as subscriber | Feb 27, 2024 | 6.1 | 19 | NO | NO |
CVE-2021-34661MEDIUM The WP Fusion Lite WordPress plugin is vulnerable to Cross-Site Request Forgery via the `show_logs_section` function found in the ~/includes/admin/logging/class-log-handler.php fil | Aug 9, 2021 | 4.7 | 18 | NO | NO |
CVE-2024-32455MEDIUM Missing Authorization vulnerability in Very Good Plugins Fatal Error Notify.This issue affects Fatal Error Notify: from n/a through 1.5.2. | Apr 16, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Verygoodplugins.
Media articles that mention a CVE ID that affects a product developed by Verygoodplugins — matched by CVE ID, not by vendor name.