Webdevstudios develops a suite of WordPress plugins and extensions, including Custom Post Type UI, iThemes PayPal Pro, Taxonomy Switcher, and WDS Multisite Aggregate, that extend functionality across WordPress site management and e-commerce workflows. The observed vulnerability signal centers on cross-site scripting weaknesses in web page generation, a characteristic risk for client-side plugin code operating within WordPress environments where output sanitization is critical to security boundaries.
The number and severity of CVEs published that impact products developed by Webdevstudios over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1623MEDIUM The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug information to a user supplied email, which could allow attackers to | Apr 24, 2023 | 6.5 | 21 | NO | NO |
CVE-2015-10013MEDIUM A vulnerability was found in WebDevStudios taxonomy-switcher Plugin up to 1.0.3 on WordPress. It has been classified as problematic. Affected is the function taxonomy_switcher_init | Jan 5, 2023 | 6.1 | 21 | NO | NO |
CVE-2025-12826MEDIUM The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.18.0. This is due to the plugin not verifying that a user | Dec 4, 2025 | 4.8 | 20 | NO | NO |
CVE-2015-10120MEDIUM A vulnerability, which was classified as problematic, was found in WDS Multisite Aggregate Plugin up to 1.0.0 on WordPress. Affected is the function update_options of the file incl | Jul 10, 2023 | 6.1 | 20 | NO | NO |
CVE-2015-9373MEDIUM PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). | Aug 28, 2019 | 6.1 | 20 | NO | NO |
CVE-2025-14056MEDIUM The Custom Post Type UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter during custom post type import in all versions up to, and includ | Dec 13, 2025 | 4.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webdevstudios.
Media articles that mention a CVE ID that affects a product developed by Webdevstudios — matched by CVE ID, not by vendor name.