Wow Estore

First CVE: Jun 14, 2021Active for: 5 yearsTotal CVEs: 14

Wow Estore maintains a small suite of web-based UI and marketing tools, including menu, button, and popup components for e-commerce sites. The vendor's vulnerability disclosures, though limited in scope, span multiple product lines and reflect the input-handling complexities inherent to client-side and form-building software. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wow Estore over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 14, 2021
5 years ago
Most Recent CVE
Jun 22, 2023
1,129 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection
Aug 30, 20218.827NONO
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin <= 2.1.2 at WordPress.
May 18, 20227.224NONO
The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the
Aug 9, 20217.224NONO
The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into
Jun 14, 20217.224NONO
Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin <= 5.2 at WordPress.
May 20, 20224.919NONO
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.3 versions.
Jun 22, 20234.817NONO
The Float menu WordPress plugin before 4.3.1 does not have CSRF check in place when deleting menu, which could allow attackers to make a logged in admin delete them via a CSRF atta
Feb 21, 20224.314NONO

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
Severity distribution among all CVEs352,427 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required2 (28.6%)
Privileges Required
Low1 (14.3%)
High5 (71.4%)
None1 (14.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wow Estore.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wow Estore — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wow Estore's Products

Top CWEs