Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Cool Plugins — Vulnerabilities & Security Advisories 8

Browse all 8 CVE security advisories affecting Cool Plugins. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Cool Plugins develops WordPress extensions that enhance website functionality with themes and plugins. Historically, their products have frequently contained remote code execution (RCE) and cross-site scripting (XSS) vulnerabilities, often stemming from insufficient input validation and sanitization. Privilege escalation issues have also been common, allowing unauthorized access to administrative functions. While no major public security incidents have been documented, the 7 CVEs on record indicate consistent security flaws that could enable complete website compromise. Their plugin architecture typically lacks robust access controls, making them attractive targets for attackers seeking to deploy malware or steal sensitive data.

Found 3 results / 8 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2023-36681 WordPress Cryptocurrency Widgets – Price Ticker & Coins List plugin <= 2.6.2 - Broken Access Control vulnerability — Cryptocurrency Widgets – Price Ticker & Coins List CWE-862 5.3 Medium 2024-12-13
CVE-2024-43304 WordPress Cryptocurrency Widgets plugin <= 2.8.0 - Reflected Cross Site Scripting (XSS) vulnerability — Cryptocurrency Widgets – Price Ticker & Coins List CWE-79 7.1 High 2024-08-18
CVE-2024-27953 WordPress Cryptocurrency Widgets – Price Ticker & Coins List Plugin <= 2.6.8 is vulnerable to Broken Access Control — Cryptocurrency Widgets – Price Ticker & Coins List CWE-862 4.7 Medium 2024-03-13

This page lists every published CVE security advisory associated with Cool Plugins. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.