Webmaster Source maintains a narrow portfolio of web-development and content-management tools, including products such as GoCodes and WP125 that serve small-to-medium web publishers. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webmaster Source over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25073HIGH The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a logged in admin delete them via a | Jan 24, 2022 | 8.8 | 27 | NO | NO |
CVE-2015-9398HIGH The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection. | Sep 20, 2019 | 8.8 | 22 | NO | NO |
CVE-2013-2700MEDIUM Cross-site request forgery (CSRF) vulnerability in the Add/Edit page (adminmenus.php) in the WP125 plugin before 1.5.0 for WordPress allows remote attackers to hijack the authentic | May 14, 2014 | 6.8 | 18 | NO | NO |
CVE-2015-9397MEDIUM The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php deletegc XSS. | Sep 20, 2019 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webmaster Source.
Media articles that mention a CVE ID that affects a product developed by Webmaster Source — matched by CVE ID, not by vendor name.