Yoohooplugins develops a small portfolio of WordPress plugins, including Sitewide Notice and When Last Login, that extend administrative and user-interface capabilities on WordPress sites. The durable signal in its vulnerability profile centers on web-application input-handling issues, specifically cross-site request forgery and cross-site scripting flaws that are characteristic of plugin-based WordPress extensions. Current severity, exploitation activity, and disclosure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yoohooplugins over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27461HIGH Cross-Site Request Forgery (CSRF) vulnerability in Yoohoo Plugins When Last Login plugin <= 1.2.1 versions. | Nov 22, 2023 | 8.8 | 25 | NO | NO |
CVE-2021-24592MEDIUM The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in frontend pages, allowing high privilege users to perform Cross-S | Aug 30, 2021 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yoohooplugins.
Media articles that mention a CVE ID that affects a product developed by Yoohooplugins — matched by CVE ID, not by vendor name.