Wonderplugin develops a set of WordPress plugins including audio, video, PDF embedding, and slider components with a history of application-layer input-handling vulnerabilities centered on cross-site scripting and SQL injection. These weakness classes reflect the web-facing nature of plugin code and the common pitfalls of user-supplied content processing in WordPress environments; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wonderplugin over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2199MEDIUM Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via t | Mar 3, 2015 | 6.5 | 26 | NO | YES |
CVE-2024-24877MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magic Hills Pty Ltd Wonder Slider Lite allows Reflected XSS.This issue affects | Feb 8, 2024 | 6.1 | 19 | NO | NO |
CVE-2021-24541MEDIUM The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which could allow users with a role as low as Contributor to perform | Aug 16, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-24540MEDIUM The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which could allow users with a role as low as Contributor to perf | Aug 16, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wonderplugin.
Media articles that mention a CVE ID that affects a product developed by Wonderplugin — matched by CVE ID, not by vendor name.