Webcraftplugins develops the Image Map Pro plugin, a web-based tool for creating interactive image maps that faces a recurring set of web-application input-handling and authorization weaknesses including cross-site scripting, cross-site request forgery, and missing authorization controls. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webcraftplugins over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9585MEDIUM The Image Map Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'save_project' function with an arbitrary shortcode in versions up to, and including, 6. | Oct 25, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-9584MEDIUM The Image Map Pro plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the AJAX functions in versions up to | Oct 25, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-3411MEDIUM The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.0. Th | Jun 27, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-3412MEDIUM The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0. T | Jun 27, 2023 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webcraftplugins.
Media articles that mention a CVE ID that affects a product developed by Webcraftplugins — matched by CVE ID, not by vendor name.