CVE Tools

Essentialplugin

3 CVEs tracked since 2023. Since Feb 2023, none of them reached CISA KEV.

Essentialplugin CVEs per month

Feb 2023 to Feb 2023. Point at a month, or focus the strip and use the arrow keys.
Essentialplugin CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0230

Products

The products that kept showing up in Essentialplugin's monthly top three, with their CVEs summed over those months.

  1. Download Post Category Image With Grid and Slider11 month
  2. Product Slider and Carousel With Category With Woocommerce11 month
  3. Wp Blog and Widget11 month

Latest CVEs

The 13 most recently published vulnerabilities affecting Essentialplugin.

  1. CVE-2026-8681Essential Chat Support <= 1.0.1 - Missing Authorization to Unauthenticated Settings Reset via 'ecs_reset_settings' Parameter5.3
  2. CVE-2026-6443Essentialplugin Plugins (Various Versions) - Injected Backdoor9.8
  3. CVE-2025-13612Album and Image Gallery Plus Lightbox <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin's Shortcode6.4
  4. CVE-2026-0727Accordion and Accordion Slider <= 1.4.5 - Missing Authorization to Authenticated (Contributor+) Attachment Metadata Modification5.4
  5. CVE-2024-4194Album and Image Gallery plus Lightbox <= 2.0 - Unauthenticated Arbitrary Shortcode Execution6.5
  6. CVE-2023-38516WordPress Audio Player with Playlist Ultimate Plugin <= 1.2.2 is vulnerable to Cross Site Scripting (XSS)6.5
  7. CVE-2022-45818WordPress Hero Banner Ultimate Plugin <= 1.3.4 is vulnerable to Cross Site Scripting (XSS)6.5
  8. CVE-2022-38077WordPress Popup Anything Plugin <= 2.2.1 is vulnerable to Cross Site Request Forgery (CSRF)4.3
  9. CVE-2022-4791Product Slider and Carousel with Category for WooCommerce < 2.8 - Contributor+ Stored XSS via Shortcode5.4
  10. CVE-2022-4747Post Category Image With Grid and Slider < 1.4.8 - Contributor+ Stored XSS via Shortcode5.4
  11. CVE-2022-4824WP Blog and Widget < 2.3.1 - Contributor+ Stored XSS via Shortcode5.4
  12. CVE-2022-2115Popup Anything < 2.1.7 - Reflected Cross-Site Scripting6.1
  13. CVE-2021-24883Popup Anything < 2.0.4 - Contributor+ Stored Cross-Site Scripting5.4

The record

Peak rank
#200 in Feb 2023
Busiest month shown
Feb 2023, 3 CVEs
Months with a KEV entry
0 since Feb 2023
Monthly snapshots
1 since 2023
Essentialplugin's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store