Videousermanuals operates a white-label content management system whose vulnerability surface centers on web-application input-handling issues, primarily cross-site scripting and cross-site request forgery. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Videousermanuals over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4302HIGH The White Label CMS WordPress plugin before 2.5 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Inject | Jan 2, 2023 | 7.2 | 33 | NO | NO |
CVE-2012-5387MEDIUM Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers to hijack the authentication of | Oct 24, 2012 | 6.8 | 31 | NO | YES |
CVE-2022-0422MEDIUM The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, l | Mar 7, 2022 | 6.1 | 28 | NO | YES |
CVE-2026-11898MEDIUM The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due to insufficient input sani | Jul 11, 2026 | 4.4 | 27 | NO | NO |
Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remote authenticated administrators to inject arbitrary web scri | Oct 24, 2012 | 3.5 | 23 | NO | YES |
CVE-2024-4280MEDIUM The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin function in all versions up to, an | May 14, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Videousermanuals.
Media articles that mention a CVE ID that affects a product developed by Videousermanuals — matched by CVE ID, not by vendor name.