Wpeka develops WordPress plugins including cookie-consent, ad-management, and legal-pages tools that extend functionality across a significant segment of WordPress-powered websites. The recurring vulnerability pattern centers on input-handling and access-control weaknesses endemic to plugin architecture: cross-site scripting flaws in web-page generation, missing authorization checks, and improper handling of formula injection in CSV exports. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpeka over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-62984MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter wpadcenter allows Stored XSS.This issue affects WP AdCenter: | Oct 27, 2025 | 6.5 | 20 | NO | NO |
CVE-2023-23678HIGH Improper Neutralization of Formula Elements in a CSV File vulnerability in WPEkaClub WP Cookie Consent ( for GDPR, CCPA & ePrivacy ).This issue affects WP Cookie Consent ( for GDPR | Nov 7, 2023 | 7.2 | 20 | NO | NO |
CVE-2021-25106MEDIUM The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logi | Feb 7, 2022 | 5.4 | 20 | NO | NO |
CVE-2025-53278MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter wpadcenter allows Stored XSS.This issue affects WP AdCenter: | Jun 27, 2025 | 6.5 | 18 | NO | NO |
CVE-2025-31860MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter wpadcenter allows Stored XSS.This issue affects WP AdCenter: | Apr 1, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-4869MEDIUM The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Client-IP’ header in all versions up to, and includin | Jun 26, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-10113MEDIUM The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpadcenter_ad shortcode in all versions up to, and inc | Nov 15, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-8317MEDIUM The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ad_alignment’ attribute in all versions up to, and including, | Sep 6, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-3599MEDIUM The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the gdpr_policy_process_del | May 2, 2024 | 5.3 | 16 | NO | NO |
CVE-2024-11724MEDIUM The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plugin for WordPress is vulnerable to unauthorized modification | Dec 12, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpeka.
Media articles that mention a CVE ID that affects a product developed by Wpeka — matched by CVE ID, not by vendor name.