Wpbean develops a focused suite of WordPress plugins and add-ons, including Elementor extensions, contact-form utilities, and content-display components that extend WordPress functionality for site builders and content managers. The vendor's vulnerability profile centers on input-handling and code-generation weaknesses endemic to web plugins, specifically cross-site scripting and code-injection flaws that arise from the intersection of user-controlled content, template rendering, and dynamic code execution in WordPress environments. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpbean over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11038HIGH The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordPress is vulnerable to arbitrary shortcode execution via wpb_pcf_ | Nov 19, 2024 | 7.3 | 23 | NO | NO |
CVE-2025-58793MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBean WPB Elementor Addons wpb-elementor-addons allows Stored XSS.This issue | Sep 5, 2025 | 6.5 | 21 | NO | NO |
CVE-2023-0370MEDIUM The WPB Advanced FAQ WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is | Mar 20, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-13664MEDIUM The WP Post List Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpb_post_list_table' shortcode in all versions up to, and including, 1.0. | Jan 30, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-34791MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpbean WPB Elementor Addons allows Stored XSS.This issue affects WPB El | Jun 3, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-4896MEDIUM The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.0.9 due to insufficient i | May 22, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-3063MEDIUM The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the output of 'tags' added to widgets in all versions up to, and including, 1.0.9 due | May 30, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpbean.
Media articles that mention a CVE ID that affects a product developed by Wpbean — matched by CVE ID, not by vendor name.