WP Athletics Project maintains a WordPress-focused plugin for managing athletic event schedules and related functionality, representing a niche segment of the WordPress plugin ecosystem. The observed vulnerability pattern centers on cross-site scripting weaknesses in the plugin's web page generation, which is a recurring concern in WordPress plugins handling user-supplied or templated content. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Athletics Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1549MEDIUM The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor does it escape the values when outputting them back in the adm | Jun 13, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-1773MEDIUM The WP Athletics WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting | Jun 13, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Athletics Project.
Media articles that mention a CVE ID that affects a product developed by Wp Athletics Project — matched by CVE ID, not by vendor name.