Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpdeveloper

First CVE: Aug 12, 2019Active for: 7 yearsTotal CVEs: 141
33.5
VTI Score
Medium

WPDeveloper produces a suite of WordPress plugins and extensions that extend the functionality of WordPress-based websites, spanning page builders, content embedding, review systems, and redirects management. The vulnerability profile across this portfolio reflects the exposure inherent to web-facing plugins: recurring weakness classes include cross-site scripting, missing authorization controls, sensitive information exposure, cross-site request forgery, and untrusted deserialization—flaws that arise naturally in the plugin ecosystem where code executes in the context of WordPress sites and interacts with user-supplied content. A meaningful share of the vendor's disclosures reach critical severity, reflecting the potential for remote code execution and site compromise through these classes. Defenders deploying WPDeveloper's plugins should prioritize patches for authorization and input-handling flaws, as compromised plugins represent a common vector for website defacement and malware distribution; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
141
Total CVEs
More Total CVEs than 99% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpdeveloper over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2019
6 years ago
Most Recent CVE
Jun 15, 2026
39 days ago

Products(13 total)

Top CVEs

Signals from CVEs in this vendor scope (141 CVEs).

141 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-1698CRITICAL
The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' par
Feb 27, 20249.881NOYES
CVE-2023-32243CRITICAL
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 throu
May 12, 20239.881NOYES
CVE-2023-6623CRITICAL
The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may
Jan 15, 20249.868NOYES
CVE-2022-0349CRITICAL
The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injecti
Mar 7, 20229.860NOYES
CVE-2023-2833HIGH
The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' funct
Jun 6, 20238.834NONO
CVE-2023-4402CRITICAL
The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products f
Oct 20, 20239.830NONO
CVE-2022-46809CRITICAL
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-
Nov 7, 20239.829NONO
CVE-2021-24356HIGH
In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/acti
Jun 14, 20218.828NONO
CVE-2021-24354HIGH
A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authentic
Jun 14, 20218.828NONO
CVE-2025-24752MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite
Apr 17, 20256.127NOYES
View all 141 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products141 CVEs
73%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network141 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low139 (98.6%)
High2 (1.4%)
Unknown0 (0.0%)
User Interaction
None67 (47.5%)
Unknown0 (0.0%)
Required74 (52.5%)
Privileges Required
Low103 (73.0%)
High3 (2.1%)
None35 (24.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (141 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
3.5% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpdeveloper.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpdeveloper — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpdeveloper's Products

View all 5 CNAs →

Top CWEs