Wpexperts develops a portfolio of WordPress plugins spanning email delivery, membership management, store localization, authentication, and e-commerce licensing, serving websites that rely on WordPress extensibility for business-critical functionality. The vulnerability footprint concentrates on web-application layer weaknesses endemic to plugin development: cross-site scripting, cross-site request forgery, SQL injection, and authorization bypasses recur across the product line, reflecting the complexity of integrating user input handling and permission enforcement in the WordPress ecosystem. While the vendor's disclosures span a modest product count, the prominence of these plugins in WordPress deployments across the web makes the weakness classes structurally significant to defenders managing WordPress infrastructure. Defenders should monitor this vendor's updates for plugins in use and prioritize patches addressing authorization and injection flaws in internet-facing WordPress instances; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpexperts over time
Signals from CVEs in this vendor scope (55 CVEs).
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6875CRITICAL The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification | Jan 11, 2024 | 9.8 | 90 | NO | YES |
CVE-2023-3139MEDIUM The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered. | Jul 4, 2023 | 6.1 | 28 | NO | YES |
CVE-2021-24755HIGH The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authentic | Nov 29, 2021 | 8.8 | 28 | NO | NO |
CVE-2023-6620HIGH The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a SQL injection exploita | Jan 15, 2024 | 7.2 | 27 | NO | NO |
CVE-2023-52233CRITICAL Missing Authorization vulnerability in Post SMTP Post SMTP Mailer/Email Log.This issue affects Post SMTP Mailer/Email Log: from n/a through 2.8.6. | Jun 11, 2024 | 9.8 | 26 | NO | NO |
CVE-2026-48838HIGH Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions. | Jun 15, 2026 | 7.1 | 25 | NO | NO |
CVE-2024-5207HIGH The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for WordPress is vulnerable to time-based SQL Injection via the s | May 30, 2024 | 7.2 | 25 | NO | NO |
CVE-2019-25150HIGH The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers to present phishing forms or co | Jun 7, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-2352HIGH The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perfor | Sep 26, 2022 | 7.2 | 25 | NO | NO |
CVE-2022-1589HIGH The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unaut | May 30, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (55 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpexperts.
Media articles that mention a CVE ID that affects a product developed by Wpexperts — matched by CVE ID, not by vendor name.