Winwar develops a focused suite of WordPress plugins for content syndication, social media integration, and e-commerce enhancement, a narrow but notably present niche in the plugin ecosystem. The recurring vulnerability classes—cross-site scripting, cross-site request forgery, and sensitive information exposure—reflect the web-facing and user-interaction demands of WordPress plugin development. Current vulnerability counts and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Winwar over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23724HIGH Cross-Site Request Forgery (CSRF) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions. | May 23, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-28421HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Winwar Media WordPress Email Marketing Plugin – WP Email Capture.This issue affects WordPress Email Mark | Dec 21, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-23728MEDIUM Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Winwar Media WP Flipclock plugin <= 1.7.4 versions. | Mar 23, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-23723MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions. | May 2, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-24005MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media Inline Tweet Sharer – Twitter Sharing Plugin plugin <= 2.5.3 versions. | Apr 25, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-23722MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP eBay Product Feeds plugin <= 3.3.1 versions. | Mar 23, 2023 | 4.8 | 18 | NO | NO |
CVE-2014-4525MEDIUM Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.1 and earlier for WordPress allows remote attackers to injec | Dec 27, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Winwar.
Media articles that mention a CVE ID that affects a product developed by Winwar — matched by CVE ID, not by vendor name.