Wow Company's vulnerability footprint centers on a focused set of WordPress-related plugins and tools, including modal window, counter box, button generator, and coding utilities, that serve web developers and site maintainers. While the vendor's disclosures span multiple products, each remains modestly scoped in deployment and function, reflecting the niche positioning of browser-based and WordPress-ecosystem tooling. The exposure does not cluster around a singular weakness class pattern, suggesting vulnerabilities arise from varied design or implementation contexts rather than a systemic architectural issue. Defenders tracking this vendor should monitor updates for any products in active use on production sites, though the portfolio's specialized audience and scope limit broad organizational risk. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wow Company over time
Signals from CVEs in this vendor scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25052HIGH The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// | Jan 10, 2022 | 8.8 | 40 | NO | YES |
CVE-2024-6926CRITICAL The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated | Sep 4, 2024 | 9.8 | 39 | NO | YES |
CVE-2021-25054HIGH The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerabilit | Jan 10, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-25051HIGH The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// prot | Jan 10, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-35629CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Easy Digital Downloads – Recent Purchases allow | Jun 4, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-2245HIGH The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such ac | Aug 1, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-25053HIGH The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocol | Jan 10, 2022 | 8.8 | 27 | NO | NO |
CVE-2024-3476HIGH The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, suc | May 2, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-24717HIGH Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window modal-window allows Cross Site Request Forgery.This issue affects Modal Window: from n/a through <= 6.1. | Jan 24, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-3474HIGH The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, s | May 2, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (50 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wow Company.
Media articles that mention a CVE ID that affects a product developed by Wow Company — matched by CVE ID, not by vendor name.