Wpbrigade develops a modestly sized portfolio of WordPress plugins focused on authentication, social-media integration, and user interface enhancements. Its vulnerability exposure concentrates on application-layer input-handling and authorization issues endemic to WordPress plugin development, including cross-site scripting, SQL injection, and missing authorization controls. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpbrigade over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15872CRITICAL The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings. | Sep 3, 2019 | 9.8 | 31 | NO | NO |
CVE-2022-4622MEDIUM The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is | Feb 21, 2023 | 5.4 | 20 | NO | NO |
CVE-2022-41839MEDIUM Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking settings. | Nov 18, 2022 | 5.3 | 20 | NO | NO |
CVE-2022-4625MEDIUM The Login Logout Menu WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users w | Jan 23, 2023 | 5.4 | 19 | NO | NO |
CVE-2021-24486MEDIUM The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the align and like_button_size parameters of its SSB shortcode, whi | Aug 23, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-24656MEDIUM The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the s | Oct 11, 2021 | 4.8 | 18 | NO | NO |
CVE-2022-0347MEDIUM The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter before outputting it back in an attribute, leading to a Ref | Mar 7, 2022 | 6.1 | 17 | NO | NO |
CVE-2019-15871MEDIUM The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings. | Sep 3, 2019 | 4.3 | 17 | NO | NO |
CVE-2024-13610MEDIUM The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perf | Apr 15, 2025 | 4.8 | 16 | NO | NO |
CVE-2023-5845MEDIUM The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthenticated visitors in some meta tags | Nov 27, 2023 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpbrigade.
Media articles that mention a CVE ID that affects a product developed by Wpbrigade — matched by CVE ID, not by vendor name.