Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpcode

First CVE: Mar 6, 2023Active for: 3 yearsTotal CVEs: 3

Wpcode is a WordPress plugin that provides code-injection and custom-functionality capabilities to site administrators, presenting a narrowly scoped but authorization-sensitive attack surface. The vulnerability profile centers on improper authorization controls, a structural concern for administrative plugins that manage elevated execution contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
3
Total CVEs
More Total CVEs than 72% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpcode over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2023
3 years ago
Most Recent CVE
Aug 7, 2023
1,082 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-3524MEDIUM
The WPCode WordPress plugin before 2.0.13.1 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting
Aug 7, 20236.119NONO
CVE-2023-1624MEDIUM
The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be deleted is inside the expected folder. This could allow attack
Apr 24, 20236.517NONO
CVE-2023-0328MEDIUM
The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authentic
Mar 6, 20234.317NONO
View all 3 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products3 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (33.3%)
Unknown0 (0.0%)
Required2 (66.7%)
Privileges Required
Low1 (33.3%)
High0 (0.0%)
None2 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpcode.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpcode — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpcode's Products

View all 1 CNAs →

Top CWEs