Xyzscripts produces a narrow line of WordPress and web-based utility plugins, including newsletter management, contact form handling, and code-insertion tools that appeal to site administrators seeking minimal PHP customization. The vendor's vulnerabilities skew toward serious outcomes, concentrating in web-layer input-handling and serialization weakness classes—CSRF, cross-site scripting variants, and untrusted deserialization—that are characteristic of server-side plugins handling user-supplied content and administrative data. Defenders should treat updates to these plugins as priority where they are deployed, particularly in exposed administrative interfaces; live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xyzscripts over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36727CRITICAL The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFiel | Jun 7, 2023 | 9.8 | 27 | NO | NO |
CVE-2012-6629MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allow remote attackers to hijack the authentication of a | Jan 16, 2014 | 6.8 | 22 | NO | NO |
CVE-2017-20054MEDIUM A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads | Jun 16, 2022 | 5.4 | 20 | NO | NO |
CVE-2024-7420MEDIUM The Insert PHP Code Snippet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6. This is due to missing or incorrect nonce | Aug 15, 2024 | 6.5 | 19 | NO | NO |
CVE-2017-20053MEDIUM A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulati | Jun 16, 2022 | 4.3 | 18 | NO | NO |
CVE-2012-6628MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the Newsletter Manager plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via th | Jan 16, 2014 | 4.3 | 18 | NO | NO |
CVE-2012-6627MEDIUM Cross-site scripting (XSS) vulnerability in admin/test_mail.php in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web scr | Jan 16, 2014 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xyzscripts.
Media articles that mention a CVE ID that affects a product developed by Xyzscripts — matched by CVE ID, not by vendor name.