Welaunch develops a focused set of WordPress plugins addressing privacy compliance and localization, with a consistent vulnerability pattern centered on web application input-handling and access-control issues including cross-site scripting, output-encoding failures, and missing authorization checks. These are characteristic risks in plugins that process user input and manage administrative capabilities within a shared WordPress environment; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Welaunch over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24814CRITICAL The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data with | Feb 1, 2022 | 9.6 | 30 | NO | NO |
CVE-2024-11069CRITICAL The WordPress GDPR plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'WordPress_GDPR_Data_Delete::check_action' function in a | Nov 19, 2024 | 9.1 | 28 | NO | NO |
CVE-2022-0220MEDIUM The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data with | Feb 1, 2022 | 6.1 | 28 | NO | YES |
CVE-2022-28290MEDIUM Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector pa | Apr 25, 2022 | 6.1 | 25 | NO | YES |
CVE-2024-10388MEDIUM The WordPress GDPR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_firstname' and 'gdpr_lastname' parameters in all versions up to, and including, 2 | Nov 19, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Welaunch.
Media articles that mention a CVE ID that affects a product developed by Welaunch — matched by CVE ID, not by vendor name.