WP Buy's vulnerability footprint centers on a small collection of WordPress plugins spanning content protection, analytics, user management, and marketing automation functionality. The disclosed issues cluster around a plugin-oriented codebase where web application input handling and access control represent the recurring exposure patterns. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Buy over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4305CRITICAL The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated at | Jan 23, 2023 | 9.8 | 64 | NO | YES |
CVE-2021-24829HIGH The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authent | Nov 8, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-24188HIGH Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install | May 14, 2021 | 8.8 | 28 | NO | NO |
CVE-2024-6690MEDIUM The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites | May 15, 2025 | 6.1 | 27 | NO | YES |
CVE-2021-24847HIGH The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanit | Nov 17, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-24195HIGH Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any | May 14, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-24194HIGH Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install | May 14, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-24193HIGH Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plug | May 14, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-24190HIGH Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any | May 14, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-15831HIGH The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page. | Aug 30, 2019 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Buy.
Media articles that mention a CVE ID that affects a product developed by Wp Buy — matched by CVE ID, not by vendor name.