Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

kaizencoders — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting kaizencoders. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Kaizencoders develops WordPress and WooCommerce plugins for e-commerce and website functionality, with 15 CVEs recorded primarily involving RCE, XSS, and privilege escalation vulnerabilities. Their plugins often contain insufficient input validation and improper access controls, leading to authenticated and unauthenticated exploits. Notable incidents include multiple critical flaws allowing complete site compromise through file uploads and nonce bypasses. Security researchers have consistently identified similar patterns across their products, indicating systemic issues in secure coding practices. Their plugins remain attractive targets due to widespread installation in vulnerable e-commerce environments.

CVE ID Title CVSS Severity Published
CVE-2026-73362 WordPress URL Shortify plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability — URL Shortify CWE-79 7.1 High 2026-08-18
CVE-2026-25392 WordPress Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress plugin <= 1.4.0 - Open Redirection vulnerability — Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress CWE-601 4.7 Medium 2026-02-19
CVE-2026-25385 WordPress URL Shortify plugin <= 1.12.3 - Server Side Request Forgery (SSRF) vulnerability — URL Shortify CWE-918 5.5 Medium 2026-02-19
CVE-2026-1277 URL Shortify <= 1.12.1 - Unauthenticated Open Redirect via 'redirect_to' Parameter — URL Shortify – Simple and Easy URL Shortener CWE-601 4.7 Medium 2026-02-18
CVE-2025-12581 Attachments Handler <= 1.1.7 - Reflected Cross-Site Scripting — Attachments Handler CWE-79 6.1 Medium 2025-12-20
CVE-2025-58860 WordPress Enable Latex Plugin <= 1.2.16 - Cross Site Request Forgery (CSRF) Vulnerability — Enable Latex CWE-352 7.1 High 2025-09-05
CVE-2025-58857 WordPress Table of content Plugin <= 1.5.3.1 - Cross Site Request Forgery (CSRF) Vulnerability — Table of content CWE-79 7.1 High 2025-09-05
CVE-2025-32632 WordPress Automatic Ban IP Plugin <= 1.0.7 - Reflected Cross Site Scripting (XSS) vulnerability — Automatic Ban IP CWE-79 7.1 High 2025-04-11
CVE-2025-32134 WordPress URL Shortify Plugin <= 1.10.5.1 - Cross Site Scripting (XSS) vulnerability — URL Shortify CWE-79 5.9 Medium 2025-04-04
CVE-2023-47225 WordPress Short URL plugin <= 1.6.8 - Broken Access Control vulnerability — Short URL CWE-862 5.4 Medium 2025-01-02
CVE-2023-1604 Short URL <= 1.6.8 - Cross-Site Request Forgery via configuration_page — Short URL CWE-352 4.7 Medium 2024-08-17
CVE-2024-7485 Traffic Manager <= 1.4.5 - Unauthenticated Stored Cross-Site Scripting — Traffic Manager CWE-79 7.2 High 2024-08-06
CVE-2024-32138 WordPress Short URL plugin <= 1.6.8 - Cross Site Scripting (XSS) vulnerability — Short URL CWE-79 7.1 High 2024-04-15
CVE-2022-46860 WordPress Short URL Plugin <= 1.6.4 is vulnerable to SQL Injection — Short URL CWE-89 8.5 High 2023-11-06
CVE-2023-45058 WordPress Short URL Plugin <= 1.6.8 is vulnerable to Cross Site Request Forgery (CSRF) — Short URL CWE-352 4.3 Medium 2023-10-12
CVE-2023-1602 WordPress plugin Short URL 跨站脚本漏洞 — Short URL 4.4 Medium 2023-06-29

This page lists every published CVE security advisory associated with kaizencoders. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.