Zephyrwest develops a focused product line centered on the Category Posts Widget, a web-facing component where vulnerabilities have centered on improper input neutralization during page generation, particularly cross-site scripting. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zephyrwest over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1453MEDIUM The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored C | Apr 24, 2025 | 4.8 | 16 | NO | NO |
CVE-2024-9638MEDIUM The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored C | Jan 7, 2025 | 4.8 | 16 | NO | NO |
CVE-2024-6158MEDIUM The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Pos | Aug 12, 2024 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zephyrwest.
Media articles that mention a CVE ID that affects a product developed by Zephyrwest — matched by CVE ID, not by vendor name.