Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webdevstudios

First CVE: Aug 28, 2019Active for: 7 yearsTotal CVEs: 6

Webdevstudios develops a suite of WordPress plugins and extensions, including Custom Post Type UI, iThemes PayPal Pro, Taxonomy Switcher, and WDS Multisite Aggregate, that extend functionality across WordPress site management and e-commerce workflows. The observed vulnerability signal centers on cross-site scripting weaknesses in web page generation, a characteristic risk for client-side plugin code operating within WordPress environments where output sanitization is critical to security boundaries.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Webdevstudios over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 28, 2019
6 years ago
Most Recent CVE
Dec 13, 2025
223 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-1623MEDIUM
The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug information to a user supplied email, which could allow attackers to
Apr 24, 20236.521NONO
CVE-2015-10013MEDIUM
A vulnerability was found in WebDevStudios taxonomy-switcher Plugin up to 1.0.3 on WordPress. It has been classified as problematic. Affected is the function taxonomy_switcher_init
Jan 5, 20236.121NONO
CVE-2025-12826MEDIUM
The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.18.0. This is due to the plugin not verifying that a user
Dec 4, 20254.820NONO
CVE-2015-10120MEDIUM
A vulnerability, which was classified as problematic, was found in WDS Multisite Aggregate Plugin up to 1.0.0 on WordPress. Affected is the function update_options of the file incl
Jul 10, 20236.120NONO
CVE-2015-9373MEDIUM
PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Aug 28, 20196.120NONO
CVE-2025-14056MEDIUM
The Custom Post Type UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter during custom post type import in all versions up to, and includ
Dec 13, 20254.418NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (66.7%)
High2 (33.3%)
Unknown0 (0.0%)
User Interaction
None2 (33.3%)
Unknown0 (0.0%)
Required4 (66.7%)
Privileges Required
Low0 (0.0%)
High1 (16.7%)
None5 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webdevstudios.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webdevstudios — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webdevstudios's Products

View all 4 CNAs →

Top CWEs