Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Caseproof

First CVE: Mar 12, 2014Active for: 12 yearsTotal CVEs: 12
23.5
VTI Score
Low

Caseproof develops a focused line of WordPress plugins for membership, affiliate marketing, and link management that are widely deployed across small-to-medium business and creator websites. The vulnerability profile centers on web-application input-handling and authorization weaknesses—cross-site scripting, CSRF, SQL injection, and missing authorization controls—that are endemic to plugin-based extensions operating within shared WordPress environments, and the vendor's disclosures show an elevated tendency toward public exploit availability. Defenders should prioritize keeping affected plugins updated and monitor for derivative attacks targeting users of the MemberPress, PrettyLinks, and Thirsty Affiliates products; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Caseproof over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2014
12 years ago
Most Recent CVE
Apr 22, 2025
458 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-4595MEDIUM
Pretty-Link WordPress plugin 1.5.2 has XSS
Jan 10, 20206.132NOYES
CVE-2024-43956CRITICAL
Missing Authorization vulnerability in Caseproof, LLC Memberpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Memberpress: from n/a through 1
Nov 1, 20249.825NONO
CVE-2013-1636MEDIUM
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNew
Mar 12, 20144.323NOYES
CVE-2024-11299HIGH
The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.37 via the WordPress core search feature. This makes
Apr 22, 20257.521NONO
CVE-2024-5031MEDIUM
The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.11.29 via the 'mepr-user-file' shortcode. This makes
May 22, 20246.420NONO
CVE-2021-24127MEDIUM
Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-
Mar 18, 20215.419NONO
CVE-2015-9457HIGH
The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.
Oct 10, 20197.219NONO
CVE-2024-5025MEDIUM
The Memberpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arglist’ parameter in all versions up to, and including, 1.11.29 due to insufficient inpu
May 22, 20245.417NONO
CVE-2024-1412MEDIUM
The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ and 'error' parameters in all versions up to, and including, 1.11.26 due to i
Apr 9, 20246.117NONO
CVE-2022-0634MEDIUM
The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscri
Apr 25, 20224.317NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
75%
17%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (91.7%)
Unknown1 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High0 (0.0%)
Unknown1 (8.3%)
User Interaction
None5 (41.7%)
Unknown1 (8.3%)
Required6 (50.0%)
Privileges Required
Low5 (41.7%)
High1 (8.3%)
None5 (41.7%)
Unknown1 (8.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Caseproof.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Caseproof — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Caseproof's Products

View all 5 CNAs →

Top CWEs