Webfactoryltd develops a focused line of WordPress administration and utility plugins, including database management, site reset, and redirect tools that operate with elevated privileges within WordPress environments. The vendor's vulnerability exposure concentrates in web application security weaknesses endemic to plugin development: cross-site request forgery, missing or bypassable authorization controls, cross-site scripting, SQL injection, and user-controlled authorization logic that collectively reflect the difficulty of securing direct database and administrative access within a content-management framework. A meaningful share of the vendor's disclosures reach serious severity, reflecting the sensitive operations these plugins perform and the administrative context in which they run. Defenders should treat WordPress installations running these plugins as requiring vigilant patching and should audit authorization boundaries in custom administrative workflows; current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webfactoryltd over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7048CRITICAL The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state | Jan 16, 2020 | 9.1 | 33 | NO | NO |
CVE-2020-7047HIGH The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-re | Jan 16, 2020 | 8.8 | 28 | NO | NO |
CVE-2021-36908HIGH Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions. | Nov 18, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-36909HIGH Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their | Nov 18, 2021 | 8.1 | 26 | NO | NO |
CVE-2019-19915CRITICAL The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and explo | Dec 19, 2019 | 9.0 | 26 | NO | NO |
CVE-2020-6168HIGH A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (i | Jan 9, 2020 | 7.6 | 25 | NO | NO |
CVE-2020-6167HIGH A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, | Jan 9, 2020 | 8.8 | 25 | NO | NO |
CVE-2021-24142HIGH Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowi | Mar 18, 2021 | 7.2 | 24 | NO | NO |
CVE-2023-50837HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebFactory Ltd Login Lockdown – Protect Login Form.This issue affects Login Lo | Dec 29, 2023 | 7.2 | 21 | NO | NO |
CVE-2021-24424MEDIUM The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, | Jul 12, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webfactoryltd.
Media articles that mention a CVE ID that affects a product developed by Webfactoryltd — matched by CVE ID, not by vendor name.