Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wow Company

First CVE: —Active for: N/ATotal CVEs: 50

Wow Company's vulnerability footprint centers on a focused set of WordPress-related plugins and tools, including modal window, counter box, button generator, and coding utilities, that serve web developers and site maintainers. While the vendor's disclosures span multiple products, each remains modestly scoped in deployment and function, reflecting the niche positioning of browser-based and WordPress-ecosystem tooling. The exposure does not cluster around a singular weakness class pattern, suggesting vulnerabilities arise from varied design or implementation contexts rather than a systemic architectural issue. Defenders tracking this vendor should monitor updates for any products in active use on production sites, though the portfolio's specialized audience and scope limit broad organizational risk. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
50
Total CVEs
More Total CVEs than 98% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wow Company over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2021
4 years ago
Most Recent CVE
Mar 27, 2025
488 days ago

Products(20 total)

Top CVEs

Signals from CVEs in this vendor scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-25052HIGH
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http://
Jan 10, 20228.840NOYES
CVE-2024-6926CRITICAL
The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated
Sep 4, 20249.839NOYES
CVE-2021-25054HIGH
The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerabilit
Jan 10, 20228.828NONO
CVE-2021-25051HIGH
The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// prot
Jan 10, 20228.828NONO
CVE-2024-35629CRITICAL
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Easy Digital Downloads – Recent Purchases allow
Jun 4, 20249.827NONO
CVE-2022-2245HIGH
The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such ac
Aug 1, 20228.827NONO
CVE-2021-25053HIGH
The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocol
Jan 10, 20228.827NONO
CVE-2024-3476HIGH
The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, suc
May 2, 20248.825NONO
CVE-2025-24717HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window modal-window allows Cross Site Request Forgery.This issue affects Modal Window: from n/a through <= 6.1.
Jan 24, 20258.824NONO
CVE-2024-3474HIGH
The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, s
May 2, 20248.824NONO
View all 50 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products50 CVEs
58%
36%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (4.0%)
Network48 (96.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (98.0%)
High1 (2.0%)
Unknown0 (0.0%)
User Interaction
None10 (20.0%)
Unknown0 (0.0%)
Required40 (80.0%)
Privileges Required
Low5 (10.0%)
High18 (36.0%)
None27 (54.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
4.0% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wow Company.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wow Company — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wow Company's Products

View all 3 CNAs →

Top CWEs