Web Settler develops a suite of WordPress-focused plugins and extensions centered on content presentation and form handling, including form builders, image feeds, and login customization tools. The vulnerability exposure spans a modest but recurring set of products, with no clearly dominant weakness class emerging across the disclosures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Web Settler over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23796CRITICAL Improper Neutralization of Formula Elements in a CSV File vulnerability in Muneeb Form Builder | Create Responsive Contact Forms.This issue affects Form Builder | Create Responsive | Nov 7, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-23795HIGH Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Form Builder plugin <= 1.9.9.0 versions. | Jun 22, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-23671MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Layer Slider plugin <= 1.1.9.7 versions. | Jul 11, 2023 | 6.5 | 20 | NO | NO |
CVE-2021-36851MEDIUM Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – Free Testimonials Slider Plugin (WordPress plugin) via param | Apr 4, 2022 | 5.4 | 20 | NO | NO |
CVE-2021-24513MEDIUM The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cr | Sep 6, 2021 | 5.4 | 20 | NO | NO |
CVE-2022-46861MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Zia Imtiaz Custom Login Page Styler for WordPress plugin <= 6.2 versions. | May 10, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-47228MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb Layer Slider plugin <= 1.1.9.7 versions. | Nov 8, 2023 | 4.8 | 17 | NO | NO |
CVE-2023-47227MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Social Feed | All social media in one place plugin <= 1.5.4.6 versions. | Nov 8, 2023 | 4.8 | 17 | NO | NO |
CVE-2023-5661MEDIUM The Social Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialfeed' shortcode in all versions up to, and including, 1.5.4.6 due to insuf | Nov 7, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-24412MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Image Social Feed plugin <= 1.7.6 versions. | Sep 1, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Web Settler.
Media articles that mention a CVE ID that affects a product developed by Web Settler — matched by CVE ID, not by vendor name.