Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

hiddenpearls — Vulnerabilities & Security Advisories 4

Browse all 4 CVE security advisories affecting hiddenpearls. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Hiddenpearls develops web application frameworks primarily used for building dynamic content management systems. Historically, their products have been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation and insecure default configurations. While no major public security incidents have been documented, their CVE history reveals consistent patterns of authentication bypass flaws and insecure object references. The organization has shown gradual improvement in security practices over time, though legacy components remain potential attack vectors. Their continued presence in enterprise environments necessitates regular patching and security hardening to mitigate identified risks.

CVE ID Title CVSS Severity Published
CVE-2025-2111 WP Headers And Footers <= 3.1.1 - Cross-Site Request Forgery to Arbitrary Options Update — Insert Headers And Footers CWE-352 7.5 High 2025-04-19
CVE-2025-1764 LoginPress <= 3.3.1 - Cross-Site Request Forgery to Arbitrary Options Update — LoginPress | wp-login Custom Login Page Customizer CWE-352 7.5 High 2025-03-14
CVE-2024-1809 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) <= 5.2.3 - Missing Authorization — Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) CWE-497 5.4 Medium 2024-05-02
CVE-2024-1584 Analytify <= 5.2.1 - Missing Authorization to Unauthenticated Google Analytics Tracking ID Modification — Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) CWE-284 5.3 Medium 2024-05-02

This page lists every published CVE security advisory associated with hiddenpearls. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.