Wp3dprinting develops a 3D-printing software platform, 3DPrint Lite, with a vulnerability profile that skews toward serious outcomes and frequently acquires public exploit code despite a narrow product footprint. The recurring weakness classes—SQL injection, cross-site request forgery, and unrestricted file upload—reflect common web-application input-handling and access-control gaps that expose the platform to database compromise, session hijacking, and arbitrary code execution. Defenders deploying this software should prioritize patching and restrict network exposure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp3dprinting over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4436CRITICAL The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenti | Feb 5, 2024 | 9.8 | 43 | NO | YES |
CVE-2025-3429MEDIUM The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on | Apr 8, 2025 | 4.9 | 17 | NO | NO |
CVE-2025-3428MEDIUM The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'coating_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on | Apr 8, 2025 | 4.9 | 17 | NO | NO |
CVE-2025-3427MEDIUM The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'infill_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on t | Apr 8, 2025 | 4.9 | 17 | NO | NO |
CVE-2025-3430MEDIUM The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'printer_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on | Apr 8, 2025 | 4.9 | 16 | NO | NO |
CVE-2024-10480MEDIUM The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a C | Dec 6, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp3dprinting.
Media articles that mention a CVE ID that affects a product developed by Wp3dprinting — matched by CVE ID, not by vendor name.