Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpbrigade

First CVE: Sep 3, 2019Active for: 7 yearsTotal CVEs: 10
7.9
VTI Score
Low

Wpbrigade develops a modestly sized portfolio of WordPress plugins focused on authentication, social-media integration, and user interface enhancements. Its vulnerability exposure concentrates on application-layer input-handling and authorization issues endemic to WordPress plugin development, including cross-site scripting, SQL injection, and missing authorization controls. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpbrigade over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 3, 2019
6 years ago
Most Recent CVE
Apr 15, 2025
465 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-15872CRITICAL
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.
Sep 3, 20199.831NONO
CVE-2022-4622MEDIUM
The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is
Feb 21, 20235.420NONO
CVE-2022-41839MEDIUM
Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking settings.
Nov 18, 20225.320NONO
CVE-2022-4625MEDIUM
The Login Logout Menu WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users w
Jan 23, 20235.419NONO
CVE-2021-24486MEDIUM
The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the align and like_button_size parameters of its SSB shortcode, whi
Aug 23, 20215.419NONO
CVE-2021-24656MEDIUM
The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the s
Oct 11, 20214.818NONO
CVE-2022-0347MEDIUM
The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter before outputting it back in an attribute, leading to a Ref
Mar 7, 20226.117NONO
CVE-2019-15871MEDIUM
The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.
Sep 3, 20194.317NONO
CVE-2024-13610MEDIUM
The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perf
Apr 15, 20254.816NONO
CVE-2023-5845MEDIUM
The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthenticated visitors in some meta tags
Nov 27, 20235.315NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
90%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (40.0%)
Unknown0 (0.0%)
Required6 (60.0%)
Privileges Required
Low4 (40.0%)
High2 (20.0%)
None4 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpbrigade.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpbrigade — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpbrigade's Products

View all 3 CNAs →

Top CWEs