Weberge's vulnerability footprint centers on the WP Hide WordPress plugin, a narrowly scoped product used to manage site visibility and access control. The durable signal is rooted in application-layer authorization and request-validation issues, specifically cross-site request forgery and missing authorization controls that are characteristic of WordPress plugin development. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weberge over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3489MEDIUM The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers t | Nov 7, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weberge.
Media articles that mention a CVE ID that affects a product developed by Weberge — matched by CVE ID, not by vendor name.