Wbcomdesigns develops a set of WordPress and BuddyPress extensions and plugins focused on social sharing, group collaboration, and content presentation, including Activity Link Preview for BuddyPress, BuddyPress Activity Social Share, BuddyPress Group Reviews, and Custom Font Uploader. The observed vulnerability pattern centers on authorization and request-handling weaknesses—missing authorization controls, cross-site request forgery, and server-side request forgery—that are characteristic of web-plugin architectures where access control and input validation are critical attack surfaces. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wbcomdesigns over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47548CRITICAL Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress activity-link-preview-for-buddypress allows Server Side Request | May 7, 2025 | 9.8 | 25 | NO | NO |
CVE-2023-28694HIGH Cross-Site Request Forgery (CSRF) vulnerability in Wbcom Designs Wbcom Designs – BuddyPress Activity Social Share plugin <= 3.5.0 versions. | Nov 12, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-5489MEDIUM The Wbcom Designs – Custom Font Uploader plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'cfu_delete_customfont' function i | Jun 6, 2024 | 4.3 | 15 | NO | NO |
CVE-2022-2108MEDIUM The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improp | Jul 18, 2022 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wbcomdesigns.
Media articles that mention a CVE ID that affects a product developed by Wbcomdesigns — matched by CVE ID, not by vendor name.