Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Liquidweb

First CVE: Sep 8, 2019Active for: 7 yearsTotal CVEs: 10
23.0
VTI Score
Low

Liquidweb offers a suite of WordPress plugins and content-management tools, including Event Tickets, Restrict Content, and WPComplete, that serve web publishers and site administrators with ticketing, access control, and course functionality. The recurring vulnerability patterns center on authorization and access-control weaknesses—including improper authentication checks, user-controlled access keys, and sensitive-information exposure—that are characteristic of plugins managing restricted content and user boundaries. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Liquidweb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 8, 2019
6 years ago
Most Recent CVE
Jan 16, 2026
189 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-14844HIGH
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup_
Jan 16, 20268.230NONO
CVE-2019-16120HIGH
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.
Sep 8, 20198.829NONO
CVE-2024-1316MEDIUM
The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from l
Mar 4, 20246.523NONO
CVE-2024-11090HIGH
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core se
Jan 26, 20257.522NONO
CVE-2023-47668HIGH
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions.
Nov 23, 20237.521NONO
CVE-2022-45825MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions.
Mar 28, 20236.121NONO
CVE-2023-3182MEDIUM
The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could
Jul 17, 20236.119NONO
CVE-2024-13457MEDIUM
The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter
Jan 30, 20255.317NONO
CVE-2024-1053MEDIUM
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to,
Feb 22, 20244.316NONO
CVE-2024-1319MEDIUM
The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of statu
Mar 4, 20244.315NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
60%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low4 (40.0%)
High0 (0.0%)
None6 (60.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Liquidweb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Liquidweb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Liquidweb's Products

View all 4 CNAs →

Top CWEs