Vikasvatsa develops a WordPress display plugin focused on custom post functionality, presenting a narrowly scoped attack surface centered on a single product. The recurring signal in its vulnerability disclosures is web-layer input handling, specifically improper neutralization of user-supplied data that can lead to cross-site scripting, a common risk class in WordPress theme and plugin ecosystems. Current severity, exploitation status, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vikasvatsa over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48317MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Vatsa Display Custom Post allows Stored XSS.This issue affects Display C | Nov 30, 2023 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vikasvatsa.
Media articles that mention a CVE ID that affects a product developed by Vikasvatsa — matched by CVE ID, not by vendor name.