Splash Sync

Splash Sync has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Splash Sync has a vendor fix available, so running the current release closes it.

All of these findings were reported by vgo0. Splash Sync is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Splash Sync vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2024-11368

Splash Sync <= 2.0.7 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Splash Sync banner
Latestv2.1.0

Splash Sync

nanard33

Author

nanard33

0.0(0)
0/100
Last Updated
2026-08-27 (16d ago)
Active Installs
100+
Downloads
16,466
Requires WP
6.2+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2017-07-04 (9y ago)

Splash, the synchronization system of innovative companies! Splash is an innovative synchronization system for a multitude of reasons! Thanks to its declarative strategy, Splash is an open system capable of handling any type of data, whatever the complexity. Universal, it does not worry about the type of data: an invoice, a customer, a blog article, a comment, all are only objects composed of fields that will have to be synchronized. Fully Universal Change the way you manage your apps in the cloud! Splash is a data connector unlike any other. Why? It is totally universal!! Synchronize all types of data Our goal is very simple, connect and synchronize your data between all the applications you use, whatever they are. Simplify your e-Commerce management Synchronize your stocks between several merchant sites? Share your customer data between all your services? With Splash, it’s not just possible, it’s easy and without developments. More about Splash This module is part of SplashSync project. For more information about Splash Sync, the way it works and how you can use it to connect your applications, please refer our online documentation. Key features & benefits This module will give Splash access to ThirdParty, Products, Customer Orders & Invoice. Synchronize Products Stocks Centralize your products stocks from Dolibarr to any kind of applications. Merge all your customers data Once all your modules connected, use the Object Linked to identify and merge all your customers profiles into a single Splash entity. This way, all similar information will be shared and synchronized anywhere, from CRM to E-Commerce. Consolidate & Simplify your Financial Analytics If WooCommerce is you main site, orders and invoices can be automatically imported from your others E-Commerce, point-of-sale, or any other applications you may connect! Your financial analytics is easier… and with no efforts. Already Compatible Applications This plugin will provide Splash Connector for WordPress base and WooCommerce Plugin. You can use it to synchronize WordPress and WooCommerce with any of other Splash compatible application: Dolibarr, PrestaShop, Magento, Sylius, MailChimp, MailJet.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C