Igor Benic Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Igor Benic products.
Products
- Simple Giveaways3 vulnerabilities
- Simple Giveaways – Grow your business, email lists and traffic with contests2 vulnerabilities
- LeanPress1 vulnerability
- Pets1 vulnerability
- Recipe Maker For Your Food Blog from Zip Recipes1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-57663HIGH | WordPress Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.2.7 - SQL Injection vulnerabilityContributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions. CWE-89Jun 26, 2026 | CVSS8.5v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-52742HIGH | WordPress Pets Plugin <= 1.4.1 - Cross Site Scripting (XSS) VulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Igor Benic Pets pets allows Reflected XSS.This issue affects Pets: from n/a through <= 1.4.1. CWE-79Oct 22, 2025 | CVSS7.1v3.1 | EPSS0.233% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-47606MEDIUM | WordPress Simple Giveaways plugin <= 2.49.0 - Cross Site Request Forgery (CSRF) vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways giveasap allows Cross Site Request Forgery.This issue affects Simple Giveaways: from n/a through <= 2.49.0. CWE-352May 7, 2025 | CVSS4.3v3.1 | EPSS0.158% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30819HIGH | WordPress Simple Giveaways plugin <= 2.48.1 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Igor Benic Simple Giveaways giveasap allows SQL Injection.This issue affects Simple Giveaways: from n/a through <= 2.48.1. CWE-89Mar 27, 2025 | CVSS8.5v3.1 | EPSS0.422% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-23893MEDIUM | WordPress Simple Giveaways plugin <= 2.48.0 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Igor Benic Simple Giveaways allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Giveaways: from n/a through 2.48.0. CWE-862Dec 9, 2024 | CVSS5.3v3.1 | EPSS0.553% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-52483HIGH | WordPress LeanPress plugin <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Igor Benic LeanPress leanpress allows Reflected XSS.This issue affects LeanPress: from n/a through <= 1.0.0. CWE-79Dec 2, 2024 | CVSS7.1v3.1 | EPSS0.32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-31086MEDIUM | WordPress Simple Giveaways Plugin <= 2.46.0 is vulnerable to Cross Site Request Forgery (CSRF)Cross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways – Grow your business, email lists and traffic with contests plugin <= 2.46.0 versions. CWE-352Nov 9, 2023 | CVSS5.4v3.1 | EPSS0.306% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24298MEDIUM | Simple Giveaways < 2.36.2 - Unauthenticated Reflected Cross-Site Scripting (XSS)The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS | CVSS6.1v3.1 | EPSS3.45% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |