Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpeka

First CVE: Feb 7, 2022Active for: 4 yearsTotal CVEs: 11
10.8
VTI Score
Low

Wpeka develops WordPress plugins including cookie-consent, ad-management, and legal-pages tools that extend functionality across a significant segment of WordPress-powered websites. The recurring vulnerability pattern centers on input-handling and access-control weaknesses endemic to plugin architecture: cross-site scripting flaws in web-page generation, missing authorization checks, and improper handling of formula injection in CSV exports. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpeka over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 7, 2022
4 years ago
Most Recent CVE
Oct 27, 2025
270 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-62984MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter wpadcenter allows Stored XSS.This issue affects WP AdCenter:
Oct 27, 20256.520NONO
CVE-2023-23678HIGH
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPEkaClub WP Cookie Consent ( for GDPR, CCPA & ePrivacy ).This issue affects WP Cookie Consent ( for GDPR
Nov 7, 20237.220NONO
CVE-2021-25106MEDIUM
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logi
Feb 7, 20225.420NONO
CVE-2025-53278MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter wpadcenter allows Stored XSS.This issue affects WP AdCenter:
Jun 27, 20256.518NONO
CVE-2025-31860MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter wpadcenter allows Stored XSS.This issue affects WP AdCenter:
Apr 1, 20256.518NONO
CVE-2024-4869MEDIUM
The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Client-IP’ header in all versions up to, and includin
Jun 26, 20246.118NONO
CVE-2024-10113MEDIUM
The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpadcenter_ad shortcode in all versions up to, and inc
Nov 15, 20245.417NONO
CVE-2024-8317MEDIUM
The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ad_alignment’ attribute in all versions up to, and including,
Sep 6, 20245.417NONO
CVE-2024-3599MEDIUM
The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the gdpr_policy_process_del
May 2, 20245.316NONO
CVE-2024-11724MEDIUM
The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plugin for WordPress is vulnerable to unauthorized modification
Dec 12, 20244.315NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
91%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (27.3%)
Unknown0 (0.0%)
Required8 (72.7%)
Privileges Required
Low7 (63.6%)
High2 (18.2%)
None2 (18.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpeka.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpeka — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpeka's Products

View all 3 CNAs →

Top CWEs