Youngtechleads appears to develop WordPress plugins or similar web-based administrative tools, with a narrow product focus centered around user-management functionality such as member imports and database table operations. The observed vulnerability classes—cross-site request forgery and cross-site scripting—reflect the input-handling and state-change risks inherent to web administration interfaces. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Youngtechleads over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25932HIGH Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix change-table-prefix allows Cross Site Request Forgery.This issue affects Change Table Pr | Feb 29, 2024 | 8.8 | 23 | NO | NO |
CVE-2022-4663MEDIUM The Members Import plugin for WordPress is vulnerable to Self Cross-Site Scripting via the user_login parameter in an imported CSV file in versions up to, and including, 1.4.2 due | Jan 3, 2023 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Youngtechleads.
Media articles that mention a CVE ID that affects a product developed by Youngtechleads — matched by CVE ID, not by vendor name.