Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wonderplugin

First CVE: Mar 3, 2015Active for: 11 yearsTotal CVEs: 4

Wonderplugin develops a set of WordPress plugins including audio, video, PDF embedding, and slider components with a history of application-layer input-handling vulnerabilities centered on cross-site scripting and SQL injection. These weakness classes reflect the web-facing nature of plugin code and the common pitfalls of user-supplied content processing in WordPress environments; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wonderplugin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 3, 2015
11 years ago
Most Recent CVE
Feb 8, 2024
898 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-2199MEDIUM
Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via t
Mar 3, 20156.526NOYES
CVE-2024-24877MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magic Hills Pty Ltd Wonder Slider Lite allows Reflected XSS.This issue affects
Feb 8, 20246.119NONO
CVE-2021-24541MEDIUM
The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which could allow users with a role as low as Contributor to perform
Aug 16, 20215.419NONO
CVE-2021-24540MEDIUM
The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which could allow users with a role as low as Contributor to perf
Aug 16, 20215.419NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
100%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network3 (75.0%)
Unknown1 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (75.0%)
High0 (0.0%)
Unknown1 (25.0%)
User Interaction
None0 (0.0%)
Unknown1 (25.0%)
Required3 (75.0%)
Privileges Required
Low2 (50.0%)
High0 (0.0%)
None1 (25.0%)
Unknown1 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wonderplugin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wonderplugin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wonderplugin's Products

View all 3 CNAs →

Top CWEs