Wpdesk develops a focused line of WordPress and WooCommerce plugins, including Flexible Checkout Fields and Flexible Wishlist, that extend e-commerce and form-handling functionality. Its vulnerability profile centers on web application input-handling and authorization issues, with recurrent weaknesses spanning cross-site request forgery, cross-site scripting, and missing authorization checks characteristic of plugins that interact with user-supplied data and WordPress permission models. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpdesk over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36731MEDIUM The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in | Jun 7, 2023 | 6.1 | 28 | NO | YES |
CVE-2024-31267HIGH Missing Authorization vulnerability in WP Desk Flexible Checkout Fields for WooCommerce.This issue affects Flexible Checkout Fields for WooCommerce: from n/a through 4.1.2. | Jun 9, 2024 | 8.8 | 21 | NO | NO |
CVE-2024-13718MEDIUM The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1 | Feb 18, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpdesk.
Media articles that mention a CVE ID that affects a product developed by Wpdesk — matched by CVE ID, not by vendor name.