WordPress plugins represent a modestly represented but high-visibility segment of the plugin ecosystem, with vulnerability disclosures spanning a narrow set of utility and media-handling extensions such as Secure Files, The Hacker's Diet, Video Popup, and WP Print. The weakness classes associated with these plugins center on input-handling and access-control mechanisms characteristic of WordPress add-ons; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Plugins over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6420HIGH The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to ac | Jul 23, 2024 | 8.6 | 34 | NO | YES |
CVE-2025-26909CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows PHP Local Fi | Mar 27, 2025 | 9.8 | 30 | NO | NO |
CVE-2005-10002CRITICAL A vulnerability, which was classified as critical, was found in almosteffortless secure-files Plugin up to 1.1 on WordPress. Affected is the function sf_downloads of the file secur | Oct 29, 2023 | 9.8 | 30 | NO | NO |
CVE-2007-10003HIGH A vulnerability, which was classified as critical, has been found in The Hackers Diet Plugin up to 0.9.6b on WordPress. This issue affects some unknown processing of the file ajax_ | Oct 29, 2023 | 8.8 | 25 | NO | NO |
CVE-2025-2056HIGH The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.4.01 via the showFile function. T | Mar 14, 2025 | 7.5 | 22 | NO | NO |
CVE-2022-4537MEDIUM The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions | May 9, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-32518MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ono Oogami WP Chinese Conversion plugin <= 1.1.16 versions. | Aug 25, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-10825MEDIUM The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up to, and including, 5.3.01 due to insu | Nov 15, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-4962MEDIUM The Video PopUp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'video_popup' shortcode in versions up to, and including, 1.1.3 due to insufficient input sani | Jan 11, 2024 | 5.4 | 18 | NO | NO |
CVE-2013-2693MEDIUM Cross-site request forgery (CSRF) vulnerability in the Options in the WP-Print plugin before 2.52 for WordPress allows remote attackers to hijack the authentication of administrato | Apr 10, 2014 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Plugins.
Media articles that mention a CVE ID that affects a product developed by Wp Plugins — matched by CVE ID, not by vendor name.