Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vektor Inc

First CVE: Feb 27, 2023Active for: 3 yearsTotal CVEs: 31

Vektor Inc develops a focused suite of WordPress plugins and page-building tools, including products such as VK All in One Expansion Unit, VK Blocks, VK Block Patterns, and VK Filter Search that extend WordPress functionality for content management and site customization. The vendor's vulnerability profile reflects the attack surface typical of widely installed WordPress extensions—plugins that operate within the WordPress ecosystem and interface with user input, content storage, and site administration. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
5.1
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vektor Inc over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 27, 2023
3 years ago
Most Recent CVE
Mar 7, 2025
506 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-27926MEDIUM
Cross-site scripting vulnerability in Profile setting function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary sc
May 23, 20235.420NONO
CVE-2023-0937MEDIUM
The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead
Mar 20, 20236.120NONO
CVE-2023-0230MEDIUM
The VK All in One Expansion Unit WordPress plugin before 9.86.0.0 does not validate and escape some of its block options before outputting them back in a page/post where the block
Feb 27, 20235.420NONO
CVE-2023-28367MEDIUM
Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.
May 23, 20235.419NONO
CVE-2023-27925MEDIUM
Cross-site scripting vulnerability in Post function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arb
May 23, 20235.419NONO
CVE-2023-27923MEDIUM
Cross-site scripting vulnerability in Tag edit function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an
May 23, 20235.419NONO
CVE-2024-2093MEDIUM
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.95.0.1 via social meta tags. This make
Apr 9, 20245.318NONO
CVE-2023-5705MEDIUM
The VK Filter Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk_filter_search' shortcode in all versions up to, and including, 2.3.1 due
Oct 27, 20235.418NONO
CVE-2024-52268MEDIUM
Cross-site scripting vulnerability exists in VK All in One Expansion Unit versions prior to 9.100.1.0. If this vulnerability is exploited, an arbitrary script may be executed on th
Nov 13, 20244.817NONO
CVE-2024-37956MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vektor,Inc. VK All in One Expansion Unit allows Stored XSS.This issue a
Jul 20, 20245.417NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
100%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (25.0%)
Unknown0 (0.0%)
Required12 (75.0%)
Privileges Required
Low12 (75.0%)
High1 (6.3%)
None3 (18.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vektor Inc.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vektor Inc — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vektor Inc's Products

View all 4 CNAs →

Top CWEs