The WP Custom Cursors Project maintains a WordPress plugin focused on cursor customization, a narrowly scoped product where vulnerabilities cluster around web-application input-handling and request-validation weaknesses such as cross-site scripting and cross-site request forgery. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Custom Cursors Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3150HIGH The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by hi | Oct 17, 2022 | 7.2 | 24 | NO | NO |
CVE-2023-2221HIGH The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by us | Jun 19, 2023 | 7.2 | 21 | NO | NO |
CVE-2022-3151MEDIUM The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary | Oct 17, 2022 | 4.3 | 18 | NO | NO |
CVE-2022-3149MEDIUM The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perfo | Oct 17, 2022 | 6.1 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Custom Cursors Project.
Media articles that mention a CVE ID that affects a product developed by Wp Custom Cursors Project — matched by CVE ID, not by vendor name.