Webberzone develops a suite of WordPress plugins focused on search enhancement, content discovery, and knowledge management, presenting a modestly scoped but notably represented attack surface within the WordPress ecosystem. The vendor's durable vulnerability signal centers on application-layer input and session-handling weaknesses including cross-site request forgery, cross-site scripting, authentication bypass, and missing authorization checks that are characteristic of web plugins with user-facing and administrative surfaces. Defenders should track this vendor's plugin updates and audit custom configurations, particularly for deployments managing sensitive content; live severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webberzone over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47238HIGH Cross-Site Request Forgery (CSRF) vulnerability in WebberZone Top 10 – WordPress Popular posts by WebberZone plugin <= 3.3.2 versions. | Nov 9, 2023 | 8.8 | 25 | NO | NO |
CVE-2024-29142HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebberZone Better Search – Relevant search results for WordPress allows Stored | Mar 19, 2024 | 7.1 | 20 | NO | NO |
CVE-2023-0252MEDIUM The Contextual Related Posts WordPress plugin before 3.3.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embe | Feb 6, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-51677MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Knowledge Base knowledgebase allows Stored XSS.This issue affects Knowled | Nov 4, 2024 | 5.4 | 18 | NO | NO |
CVE-2020-36761MEDIUM The Top 10 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.4. This is due to missing or incorrect nonce validation on the tp | Jul 12, 2023 | 4.3 | 18 | NO | NO |
CVE-2021-4373MEDIUM The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to | Jun 7, 2023 | 4.3 | 17 | NO | NO |
CVE-2021-4400MEDIUM The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on | Jul 1, 2023 | 4.3 | 16 | NO | NO |
CVE-2023-25993MEDIUM Missing Authorization vulnerability in WebberZone Top 10 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Top 10: from n/a through 3.2.3. | Dec 9, 2024 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webberzone.
Media articles that mention a CVE ID that affects a product developed by Webberzone — matched by CVE ID, not by vendor name.