Whmpress develops extensions and integrations for WHMCS hosting management and client portal platforms, with the durable signal centered on server-side code-injection and authorization weaknesses such as PHP remote file inclusion and missing authorization checks. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Whmpress over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9193CRITICAL The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.3-revision-0 via the whmpress_d | Feb 28, 2025 | 9.8 | 40 | NO | YES |
CVE-2024-9195HIGH The WHMPress - WHMCS Client Area plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on | Feb 28, 2025 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Whmpress.
Media articles that mention a CVE ID that affects a product developed by Whmpress — matched by CVE ID, not by vendor name.