Wpwebinfotech develops WordPress plugins and web-facing tools, with its Social Auto Poster plugin serving as a focal point for vulnerability reports; the vendor's disclosures center on web-application input-handling and authorization weaknesses typical of content-management ecosystem extensions. Vulnerabilities affecting this vendor frequently acquire public exploit code, and the recurring weakness classes—cross-site scripting, missing authorization, CSRF, and unrestricted file uploads—reflect common attack vectors in plugin development where sanitization and access control boundaries are often underspecified. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpwebinfotech over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6753MEDIUM The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function | Jul 24, 2024 | 6.1 | 28 | NO | YES |
CVE-2024-6756HIGH The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all vers | Jul 24, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-49272HIGH Cross-Site Request Forgery (CSRF) vulnerability in wpweb Social Auto Poster social-auto-poster allows Cross Site Request Forgery.This issue affects Social Auto Poster: from n/a thr | Oct 20, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-6750HIGH The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all vers | Jul 24, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-47369MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweb Social Auto Poster social-auto-poster allows Reflected XSS.This issue af | Oct 5, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-6751MEDIUM The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing or incorrect nonce validati | Jul 24, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-6755MEDIUM The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_multi | Jul 24, 2024 | 5.3 | 18 | NO | NO |
CVE-2024-6752MEDIUM The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function | Jul 24, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-6754MEDIUM The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function | Jul 24, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpwebinfotech.
Media articles that mention a CVE ID that affects a product developed by Wpwebinfotech — matched by CVE ID, not by vendor name.