WPDeveloper produces a suite of WordPress plugins and extensions that extend the functionality of WordPress-based websites, spanning page builders, content embedding, review systems, and redirects management. The vulnerability profile across this portfolio reflects the exposure inherent to web-facing plugins: recurring weakness classes include cross-site scripting, missing authorization controls, sensitive information exposure, cross-site request forgery, and untrusted deserialization—flaws that arise naturally in the plugin ecosystem where code executes in the context of WordPress sites and interacts with user-supplied content. A meaningful share of the vendor's disclosures reach critical severity, reflecting the potential for remote code execution and site compromise through these classes. Defenders deploying WPDeveloper's plugins should prioritize patches for authorization and input-handling flaws, as compromised plugins represent a common vector for website defacement and malware distribution; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpdeveloper over time
Signals from CVEs in this vendor scope (141 CVEs).
141 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1698CRITICAL The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' par | Feb 27, 2024 | 9.8 | 81 | NO | YES |
CVE-2023-32243CRITICAL Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 throu | May 12, 2023 | 9.8 | 81 | NO | YES |
CVE-2023-6623CRITICAL The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may | Jan 15, 2024 | 9.8 | 68 | NO | YES |
CVE-2022-0349CRITICAL The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injecti | Mar 7, 2022 | 9.8 | 60 | NO | YES |
CVE-2023-2833HIGH The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' funct | Jun 6, 2023 | 8.8 | 34 | NO | NO |
CVE-2023-4402CRITICAL The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products f | Oct 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-46809CRITICAL Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi- | Nov 7, 2023 | 9.8 | 29 | NO | NO |
CVE-2021-24356HIGH In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/acti | Jun 14, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-24354HIGH A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authentic | Jun 14, 2021 | 8.8 | 28 | NO | NO |
CVE-2025-24752MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite | Apr 17, 2025 | 6.1 | 27 | NO | YES |
Signals from CVEs in this vendor scope (141 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpdeveloper.
Media articles that mention a CVE ID that affects a product developed by Wpdeveloper — matched by CVE ID, not by vendor name.