Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webfactoryltd

First CVE: Dec 19, 2019Active for: 7 yearsTotal CVEs: 27
16.9
VTI Score
Low

Webfactoryltd develops a focused line of WordPress administration and utility plugins, including database management, site reset, and redirect tools that operate with elevated privileges within WordPress environments. The vendor's vulnerability exposure concentrates in web application security weaknesses endemic to plugin development: cross-site request forgery, missing or bypassable authorization controls, cross-site scripting, SQL injection, and user-controlled authorization logic that collectively reflect the difficulty of securing direct database and administrative access within a content-management framework. A meaningful share of the vendor's disclosures reach serious severity, reflecting the sensitive operations these plugins perform and the administrative context in which they run. Defenders should treat WordPress installations running these plugins as requiring vigilant patching and should audit authorization boundaries in custom administrative workflows; current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Webfactoryltd over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2019
6 years ago
Most Recent CVE
Feb 25, 2025
514 days ago

Products(14 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-7048CRITICAL
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state
Jan 16, 20209.133NONO
CVE-2020-7047HIGH
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-re
Jan 16, 20208.828NONO
CVE-2021-36908HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions.
Nov 18, 20218.827NONO
CVE-2021-36909HIGH
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their
Nov 18, 20218.126NONO
CVE-2019-19915CRITICAL
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and explo
Dec 19, 20199.026NONO
CVE-2020-6168HIGH
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (i
Jan 9, 20207.625NONO
CVE-2020-6167HIGH
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings,
Jan 9, 20208.825NONO
CVE-2021-24142HIGH
Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowi
Mar 18, 20217.224NONO
CVE-2023-50837HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebFactory Ltd Login Lockdown – Protect Login Form.This issue affects Login Lo
Dec 29, 20237.221NONO
CVE-2021-24424MEDIUM
The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard,
Jul 12, 20215.419NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
67%
26%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (96.3%)
High1 (3.7%)
Unknown0 (0.0%)
User Interaction
None15 (55.6%)
Unknown0 (0.0%)
Required12 (44.4%)
Privileges Required
Low12 (44.4%)
High4 (14.8%)
None11 (40.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webfactoryltd.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webfactoryltd — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webfactoryltd's Products

View all 4 CNAs →

Top CWEs