Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kraftplugins

First CVE: Apr 18, 2024Active for: 2 yearsTotal CVEs: 13
21.2
VTI Score
Low

Kraftplugins develops WordPress plugins spanning themes and content management utilities such as Mega Elements, Wheel of Life, and Demo Importer Plus, a narrowly scoped but notably affected product line within the plugin ecosystem. Its vulnerability profile skews toward serious outcomes, with a meaningful share reaching critical severity and concentrating in web-application input-handling and authorization weakness classes—cross-site scripting and missing authorization—that recur across the plugin portfolio. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kraftplugins over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2024
2 years ago
Most Recent CVE
Feb 19, 2026
155 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-13066HIGH
The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to insufficient file type validation det
Dec 5, 20258.829NONO
CVE-2025-14478HIGH
The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the SVG file upload functionality.
Jan 17, 20267.528NONO
CVE-2025-14364HIGH
The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privilege escalation due to a missing capability check on the Ajax
Dec 18, 20258.828NONO
CVE-2024-47311CRITICAL
Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of
Nov 1, 20249.827NONO
CVE-2024-47343MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraft Plugins Mega Elements mega-elements-addons-for-elementor allows Stored X
Oct 6, 20246.519NONO
CVE-2026-25000MEDIUM
Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of
Feb 19, 20265.318NONO
CVE-2025-69091MEDIUM
Missing Authorization vulnerability in Kraft Plugins Demo Importer Plus demo-importer-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect
Dec 30, 20254.317NONO
CVE-2024-49693MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraft Plugins Mega Elements mega-elements-addons-for-elementor allows Stored X
Oct 24, 20245.417NONO
CVE-2024-9172MEDIUM
The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.1 due to insufficient input
Oct 2, 20245.417NONO
CVE-2024-37466MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kraftplugins Mega Elements.This issue affects Mega Elements: from n/a t
Jul 21, 20245.417NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
69%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (53.8%)
Unknown0 (0.0%)
Required6 (46.2%)
Privileges Required
Low10 (76.9%)
High0 (0.0%)
None3 (23.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kraftplugins.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kraftplugins — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kraftplugins's Products

View all 2 CNAs →

Top CWEs