Weblizar develops a focused suite of WordPress plugins spanning social-media integration, authentication, and site-management functions that sit within widely deployed WordPress installations. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in input-handling and code-execution weakness classes, particularly cross-site scripting, SQL injection, code injection, and cross-site request forgery, which are endemic to plugin architectures that interact with untrusted user input and administrative interfaces. The exposure recurs across products such as Pinterest Feeds, Admin Custom Login, and School Management, reflecting the vendor's footprint in WordPress ecosystems where plugin flaws can cascade to site-wide compromise. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weblizar over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1609CRITICAL The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenti | Jan 16, 2024 | 9.8 | 77 | NO | YES |
CVE-2022-46849CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar Coming Soon Page – Responsive Coming Soon & Maintenance Mode allows S | Nov 6, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-47430CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar The School Management – Education & Learning Management allows SQL In | Nov 6, 2023 | 9.8 | 28 | NO | NO |
CVE-2021-34628HIGH The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found in the ~/includes/Login-form-setting/Login-form-background.p | Aug 2, 2021 | 8.8 | 26 | NO | NO |
CVE-2019-15781HIGH The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF. | Aug 29, 2019 | 8.8 | 26 | NO | NO |
CVE-2018-5656HIGH An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php. | Jan 13, 2018 | 8.8 | 25 | NO | NO |
CVE-2024-33911HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar School Management Pro.This issue affects School Management Pro: from | May 2, 2024 | 7.2 | 21 | NO | NO |
CVE-2017-20098MEDIUM A vulnerability was found in Admin Custom Login Plugin 2.4.5.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site s | Jun 27, 2022 | 4.8 | 19 | NO | NO |
CVE-2018-5655MEDIUM An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php security parameter. | Jan 13, 2018 | 6.1 | 19 | NO | NO |
CVE-2018-5654MEDIUM An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php PFFREE_Access_Token parameter. | Jan 13, 2018 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weblizar.
Media articles that mention a CVE ID that affects a product developed by Weblizar — matched by CVE ID, not by vendor name.