Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vanquish

First CVE: Apr 5, 2021Active for: 5 yearsTotal CVEs: 19
44.0
VTI Score
High

Vanquish develops a focused line of WordPress and WooCommerce plugins, including customer management, support ticketing, and file-upload utilities, that extend e-commerce and site administration functionality. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across its plugin portfolio through web-tier weakness classes including CSRF, path traversal, missing authorization, unrestricted file uploads, and cross-site scripting—patterns endemic to form-handling and file-processing plugins that execute in a shared WordPress environment. Defenders should treat updates to these plugins as a patching priority for any WordPress installation relying on them; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vanquish over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 5, 2021
5 years ago
Most Recent CVE
Feb 20, 2026
154 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-0399HIGH
The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exp
Apr 15, 20248.134NOYES
CVE-2024-11150CRITICAL
The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in
Nov 13, 20249.829NONO
CVE-2024-10627CRITICAL
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_manage_file_chunk_upload() functi
Nov 9, 20249.829NONO
CVE-2021-24171CRITICAL
The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file
Apr 5, 20219.829NONO
CVE-2024-10820CRITICAL
The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to,
Nov 13, 20249.827NONO
CVE-2024-10625CRITICAL
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() funct
Nov 9, 20249.127NONO
CVE-2025-69376HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Traversal.This issue aff
Feb 20, 20268.626NONO
CVE-2024-13343HIGH
The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new_roles() function in all versio
Feb 1, 20258.825NONO
CVE-2025-69377HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Traversal.This issue aff
Feb 20, 20267.724NONO
CVE-2024-10626HIGH
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_uploaded_file() function
Nov 9, 20248.124NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
32%
42%
26%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.3%)
Network18 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (78.9%)
Unknown0 (0.0%)
Required4 (21.1%)
Privileges Required
Low8 (42.1%)
High0 (0.0%)
None11 (57.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vanquish.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vanquish — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vanquish's Products

View all 3 CNAs →

Top CWEs