SecAlerts
s

smackcoders

Security Risk Profile

28
/100
low

Security Risk Score

Comprehensive risk assessment based on 34 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from November 5, 2013 to present

34
Total CVEs
18
Critical+High
0
Exploited
10
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
10
Critical/High
Risk Level
28/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
3
High
15
Medium
16
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
10

Age Distribution

Common Weaknesses (CWE)

1
SQL Injection
5
2
XSS
5
3
CSRF
4
4
Code Injection
3
5
Infoleak
3

Most Affected Products

1. Smackcoders Wp Ultimate Email Marketer Plugin Wordpress10
2. Smackcoders Wp Ultimate Csv Importer Wordpress4
3. Smackcoders Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv4
4. Smackcoders Export All Posts\, Products\, Orders\, Refunds \& Users Wordpress3
5. Smackcoders Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv Wordpress3

Recent Vulnerabilities

See more →
CVE-2026-103336
CVSS 5.3medium

WordPress WP Ultimate CSV Importer plugin <= 9.1 - Sensitive Data Exposure vulnerability

Oct 1, 2026🔧 No Patch
CVE-2025-5692
CVSS 6.3EPSS 0%medium

Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Many Actions

Jul 2, 2025
CVE-2025-47690
CVSS 8.8EPSS 0%high

WordPress Lead Form Data Collection to CRM plugin <= 3.1 - Arbitrary Option Update to Privilege Escalation vulnerability

May 23, 2025🔧 No Patch
CVE-2025-31788
CVSS 5.3EPSS 0%medium

WordPress AIO Performance Profiler, Monitor, Optimize, Compress & Debug plugin <= 1.3 - Sensitive Data Exposure vulnerability

Apr 1, 2025🔧 No Patch
CVE-2025-31775
CVSS 4.3EPSS 0%medium

WordPress Google SEO Pressor for Rich snippets Plugin <= 2.0 - Cross Site Request Forgery (CSRF) vulnerability

Apr 1, 2025🔧 No Patch
CVE-2025-31530
CVSS 4.3EPSS 0%medium

WordPress Google SEO Pressor Snippet plugin <= 2.0 - Broken Access Control vulnerability

Mar 31, 2025🔧 No Patch
CVE-2025-22647
CVSS 4.3medium

WordPress AIO Performance Profiler plugin <= 1.2 - Broken Access Control vulnerability

Mar 27, 2025🔧 No Patch
CVE-2025-30810
CVSS 8.5EPSS 0%high

WordPress Lead Form Data Collection to CRM plugin <= 3.0.1 - SQL Injection vulnerability

Mar 27, 2025
CVE-2024-12315
CVSS 7.5high

Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directory

Feb 12, 2025
CVE-2025-24611
CVSS 4.9EPSS 0%medium

WordPress Export All Posts, Products, Orders, Refunds & Users Plugin <= 2.9 - Arbitrary File Read vulnerability

Jan 24, 2025

Monitor smackcoders in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.