Wpmanage develops a focused set of WordPress plugins—notably Uji Countdown and Uji Popup—that extend functionality for content presentation and user engagement on WordPress sites. The durable vulnerability signal centers on improper input neutralization during web-page generation, a web-application-layer weakness class that reflects the plugins' role in rendering user-controlled or dynamically generated content. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpmanage over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23641MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPmanage Uji Popup plugin <= 1.4.3 versions. | May 16, 2023 | 5.4 | 20 | NO | NO |
CVE-2022-3837MEDIUM The Uji Countdown WordPress plugin before 2.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site | Dec 5, 2022 | 4.8 | 19 | NO | NO |
CVE-2016-10900MEDIUM The uji-countdown plugin before 2.0.7 for WordPress has XSS. | Aug 21, 2019 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpmanage.
Media articles that mention a CVE ID that affects a product developed by Wpmanage — matched by CVE ID, not by vendor name.