Wow Estore
Wow Estore maintains a small suite of web-based UI and marketing tools, including menu, button, and popup components for e-commerce sites. The vendor's vulnerability disclosures, though limited in scope, span multiple product lines and reflect the input-handling complexities inherent to client-side and form-building software. Current severity, exploitation, and exposure counts are shown alongside this summary.
Trends Over Time
The number and severity of CVEs published that impact products developed by Wow Estore over time
Products(5 total)
Top CVEs
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24580HIGH The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection | Aug 30, 2021 | 8.8 | 27 | NO | NO |
CVE-2022-29445HIGH Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin <= 2.1.2 at WordPress. | May 18, 2022 | 7.2 | 24 | NO | NO |
CVE-2021-24521HIGH The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the | Aug 9, 2021 | 7.2 | 24 | NO | NO |
CVE-2021-24348HIGH The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into | Jun 14, 2021 | 7.2 | 24 | NO | NO |
CVE-2022-29448MEDIUM Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin <= 5.2 at WordPress. | May 20, 2022 | 4.9 | 19 | NO | NO |
CVE-2023-27452MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.3 versions. | Jun 22, 2023 | 4.8 | 17 | NO | NO |
CVE-2022-0313MEDIUM The Float menu WordPress plugin before 4.3.1 does not have CSRF check in place when deleting menu, which could allow attackers to make a logged in admin delete them via a CSRF atta | Feb 21, 2022 | 4.3 | 14 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this vendor scope (7 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID that affects a product developed by Wow Estore.
Media Mentions
Media articles that mention a CVE ID that affects a product developed by Wow Estore — matched by CVE ID, not by vendor name.