Kraftplugins develops WordPress plugins spanning themes and content management utilities such as Mega Elements, Wheel of Life, and Demo Importer Plus, a narrowly scoped but notably affected product line within the plugin ecosystem. Its vulnerability profile skews toward serious outcomes, with a meaningful share reaching critical severity and concentrating in web-application input-handling and authorization weakness classes—cross-site scripting and missing authorization—that recur across the plugin portfolio. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kraftplugins over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13066HIGH The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to insufficient file type validation det | Dec 5, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-14478HIGH The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the SVG file upload functionality. | Jan 17, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-14364HIGH The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privilege escalation due to a missing capability check on the Ajax | Dec 18, 2025 | 8.8 | 28 | NO | NO |
CVE-2024-47311CRITICAL Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of | Nov 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-47343MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraft Plugins Mega Elements mega-elements-addons-for-elementor allows Stored X | Oct 6, 2024 | 6.5 | 19 | NO | NO |
CVE-2026-25000MEDIUM Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of | Feb 19, 2026 | 5.3 | 18 | NO | NO |
CVE-2025-69091MEDIUM Missing Authorization vulnerability in Kraft Plugins Demo Importer Plus demo-importer-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect | Dec 30, 2025 | 4.3 | 17 | NO | NO |
CVE-2024-49693MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraft Plugins Mega Elements mega-elements-addons-for-elementor allows Stored X | Oct 24, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-9172MEDIUM The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.1 due to insufficient input | Oct 2, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-37466MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kraftplugins Mega Elements.This issue affects Mega Elements: from n/a t | Jul 21, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kraftplugins.
Media articles that mention a CVE ID that affects a product developed by Kraftplugins — matched by CVE ID, not by vendor name.