Wp Extended
Vendor:
First CVE: Jul 22, 2024 · Active for 2 years
11
Total CVEs
More Total CVEs than 90% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wp Extended over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 22, 2024
2 years ago
Most Recent CVE
Feb 12, 2025
531 days ago
CVE Severity & Scoring
Wp Extended11 CVEs
91%
9%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (54.5%)
Unknown0 (0.0%)
Required5 (45.5%)
Privileges Required
Low6 (54.5%)
High0 (0.0%)
None5 (45.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-37259MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended wpextended.This issue | Jul 22, 2024 | 6.1 | 27 | NO | YES |
CVE-2024-8102HIGH The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capa | Sep 4, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-8104MEDIUM The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.8 via the download_file_ajax fu | Sep 4, 2024 | 6.5 | 21 | NO | NO |
CVE-2024-9347MEDIUM The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpext-export' parameter in all versions up to, and in | Oct 17, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-8123MEDIUM The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.8 via the duplicat | Sep 4, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-8119MEDIUM The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3 | Sep 4, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-8117MEDIUM The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘selected_option’ parameter in all versions up to, and | Sep 4, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-8106MEDIUM The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 via the download_u | Sep 4, 2024 | 6.5 | 18 | NO | NO |
CVE-2024-8121MEDIUM The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user names due to a missing capability check on the wpext_change | Sep 4, 2024 | 4.3 | 17 | NO | NO |
CVE-2024-13554MEDIUM The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reorder_route() fu | Feb 12, 2025 | 5.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Wp Extended
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.12 | 1 | 6.1 | 0.5% | 0 | 0 |
| 3.0.11 | 1 | 6.1 | 0.5% | 0 | 0 |