Wpcloudplugins develops a focused line of WordPress-integrated cloud storage and file-sharing plugins, including products such as Lets Box and Share One Drive that extend WordPress environments with collaborative document access. The observed vulnerability pattern centers on cross-site scripting issues arising from improper input handling in web-page generation, a characteristic risk in plugins that broker user content and authentication flows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpcloudplugins over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42549MEDIUM Insufficient Input Validation in the search functionality of Wordpress plugin Lets-Box prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack. | Dec 13, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-42548MEDIUM Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting | Dec 13, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-42547MEDIUM Insufficient Input Validation in the search functionality of Wordpress plugin Out-of-the-Box prior to 1.20.3 allows unauthenticated user to craft a reflected Cross-Site Scripting a | Dec 13, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-42546MEDIUM Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unauthenticated user to craft a reflected Cross-Site Scripting a | Dec 13, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpcloudplugins.
Media articles that mention a CVE ID that affects a product developed by Wpcloudplugins — matched by CVE ID, not by vendor name.