Valvepress develops WordPress automation and plugin extensions focused on content distribution and SEO optimization, including products such as Automatic, Pinterest Automatic Pin, and Rankie. The observed vulnerability exposure clusters around authorization and access-control weaknesses alongside SQL-injection issues, typical of web application plugins handling user permissions and database queries. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Valvepress over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27956CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n | Mar 21, 2024 | 9.8 | 91 | NO | YES |
CVE-2021-4374CRITICAL The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option va | Jun 7, 2023 | 9.8 | 58 | NO | YES |
CVE-2021-4380CRITICAL The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the ' | Jun 7, 2023 | 9.8 | 42 | NO | YES |
CVE-2025-39510HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows SQL Injection | Aug 14, 2025 | 8.5 | 24 | NO | NO |
CVE-2025-39493HIGH Missing Authorization vulnerability in ValvePress Rankie valvepress-rankie allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rankie: from n | May 16, 2025 | 8.8 | 23 | NO | NO |
CVE-2025-39486HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Rankie valvepress-rankie allows SQL Injection.This issue affects Ra | Jun 17, 2025 | 8.5 | 22 | NO | NO |
CVE-2025-39487HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Rankie valvepress-rankie allows Reflected XSS.This issue affects Ra | Jul 4, 2025 | 7.1 | 19 | NO | NO |
CVE-2025-39511MEDIUM Missing Authorization vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue | May 16, 2025 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Valvepress.
Media articles that mention a CVE ID that affects a product developed by Valvepress — matched by CVE ID, not by vendor name.