E Plugins develops a range of WordPress-focused extensions spanning membership management, directory services, and specialized vertical applications such as fitness and healthcare directory functionality. The vendor's modest vulnerability footprint reflects its niche position in the WordPress plugin ecosystem; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by E Plugins over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-69182HIGH Incorrect Privilege Assignment vulnerability in e-plugins Institutions Directory institutions-directory allows Privilege Escalation.This issue affects Institutions Directory: from | Jan 22, 2026 | 8.8 | 31 | NO | NO |
CVE-2025-67966HIGH Incorrect Privilege Assignment vulnerability in e-plugins Lawyer Directory lawyer-directory allows Privilege Escalation.This issue affects Lawyer Directory: from n/a through <= 1.3 | Jan 22, 2026 | 8.8 | 31 | NO | NO |
CVE-2024-10547CRITICAL The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all versions up to | Nov 9, 2024 | 9.8 | 30 | NO | NO |
CVE-2025-69293HIGH Incorrect Privilege Assignment vulnerability in e-plugins Final User final-user allows Privilege Escalation.This issue affects Final User: from n/a through <= 1.2.5. | Jan 22, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-69292HIGH Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This issue affects WP Membership: from n/a through <= 1.6.4. | Jan 22, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-69188HIGH Missing Authorization vulnerability in e-plugins fitness-trainer fitness-trainer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects fitness- | Jan 22, 2026 | 7.3 | 27 | NO | NO |
CVE-2025-69187HIGH Missing Authorization vulnerability in e-plugins Final User final-user allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Final User: from n | Jan 22, 2026 | 7.3 | 27 | NO | NO |
CVE-2025-69184HIGH Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af | Jan 22, 2026 | 7.3 | 27 | NO | NO |
CVE-2020-36666HIGH The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-d | Mar 27, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-67967HIGH Missing Authorization vulnerability in e-plugins Lawyer Directory lawyer-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lawyer | Jan 22, 2026 | 7.6 | 24 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by E Plugins.
Media articles that mention a CVE ID that affects a product developed by E Plugins — matched by CVE ID, not by vendor name.