Igor Benic Vulnerabilities and Affected Products
Vulnerabilities associated with Simple Giveaways.
Products
Clear product- Simple Giveaways3 vulnerabilities
- Simple Giveaways – Grow your business, email lists and traffic with contests2 vulnerabilities
- LeanPress1 vulnerability
- Pets1 vulnerability
- Recipe Maker For Your Food Blog from Zip Recipes1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-47606MEDIUM | WordPress Simple Giveaways plugin <= 2.49.0 - Cross Site Request Forgery (CSRF) vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways giveasap allows Cross Site Request Forgery.This issue affects Simple Giveaways: from n/a through <= 2.49.0. CWE-352May 7, 2025 | CVSS4.3v3.1 | EPSS0.158% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30819HIGH | WordPress Simple Giveaways plugin <= 2.48.1 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Igor Benic Simple Giveaways giveasap allows SQL Injection.This issue affects Simple Giveaways: from n/a through <= 2.48.1. CWE-89Mar 27, 2025 | CVSS8.5v3.1 | EPSS0.422% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-23893MEDIUM | WordPress Simple Giveaways plugin <= 2.48.0 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Igor Benic Simple Giveaways allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Giveaways: from n/a through 2.48.0. CWE-862Dec 9, 2024 | CVSS5.3v3.1 | EPSS0.553% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |