Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpclever

First CVE: Mar 28, 2022Active for: 4 yearsTotal CVEs: 20
21.1
VTI Score
Low

Wpclever develops a focused line of WordPress e-commerce plugins for WooCommerce, including product management, bundling, and customer-experience extensions that integrate with store catalogs and checkout workflows. The vendor's vulnerability profile centers on application-layer input handling and access-control weaknesses such as cross-site scripting, CSRF, missing authorization, and code-injection flaws that are characteristic of plugins operating in shared WordPress environments. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpclever over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 28, 2022
4 years ago
Most Recent CVE
Jun 15, 2026
39 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-48883HIGH
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
Jun 15, 20267.526NONO
CVE-2024-50416HIGH
Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Cus
Oct 28, 20248.825NONO
CVE-2024-30537HIGH
Missing Authorization vulnerability in WPClever WPC Badge Management for WooCommerce.This issue affects WPC Badge Management for WooCommerce: from n/a through 2.4.0.
Jun 9, 20248.824NONO
CVE-2023-52127HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Product Bundles for WooCommerce.This issue affects WPC Product Bundles for WooCommerce: from n/a through 7.3.1.
Jan 5, 20248.824NONO
CVE-2023-34386HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions.
Nov 9, 20238.824NONO
CVE-2025-14767MEDIUM
The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all vers
May 13, 20265.523NONO
CVE-2024-12432HIGH
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due
Dec 18, 20248.123NONO
CVE-2024-43312HIGH
Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af
Nov 1, 20248.823NONO
CVE-2025-7496MEDIUM
The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via DOM elements in all versions up to, and including, 6.4.7 due to insuffic
Aug 19, 20256.422NONO
CVE-2022-1465MEDIUM
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading
May 16, 20226.122NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
65%
35%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (90.0%)
High2 (10.0%)
Unknown0 (0.0%)
User Interaction
None15 (75.0%)
Unknown0 (0.0%)
Required5 (25.0%)
Privileges Required
Low11 (55.0%)
High2 (10.0%)
None7 (35.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpclever.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpclever — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpclever's Products

View all 3 CNAs →

Top CWEs