The WordPress Popular Posts Project maintains a single plugin used by WordPress site administrators to display popular content, which embeds this component across a wide range of websites. Its observed vulnerability exposure centers on input-handling and file-management weaknesses, including cross-site scripting during dynamic page generation, improper initialization logic, and unrestricted file uploads that can introduce dangerous content types. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wordpress Popular Posts Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42362HIGH The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it | Nov 17, 2021 | 8.8 | 86 | NO | YES |
CVE-2022-43468HIGH External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted ex | Dec 7, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-36872MEDIUM Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type]. | Sep 23, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-20746MEDIUM Cross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | Jun 28, 2021 | 5.4 | 20 | NO | NO |
CVE-2023-45607MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Hector Cabrera WordPress Popular Posts plugin <= 6.3.2 versions. | Oct 18, 2023 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wordpress Popular Posts Project.
Media articles that mention a CVE ID that affects a product developed by Wordpress Popular Posts Project — matched by CVE ID, not by vendor name.