Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpglobus

First CVE: Jan 12, 2018Active for: 9 yearsTotal CVEs: 8

Wpglobus is a WordPress translation and localization plugin that sits within the content-management ecosystem, where its vulnerabilities center on a narrow product line. Its disclosures are characterized by web-application input-handling weaknesses, principally cross-site scripting and cross-site request forgery, which reflect the plugin's role in content processing and user interaction within WordPress environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpglobus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 12, 2018
8 years ago
Most Recent CVE
Apr 7, 2023
1,204 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-5361HIGH
The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php.
Jan 12, 20188.826NONO
CVE-2023-25711MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPGlobus WPGlobus Translate Options plugin <= 2.1.0 versions.
Apr 7, 20236.120NONO
CVE-2018-5366MEDIUM
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.php.
Jan 12, 20184.817NONO
CVE-2018-5364MEDIUM
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[browser_redirect][redirect_by_language] parameter to wp-admin/options.php.
Jan 12, 20184.817NONO
CVE-2018-5363MEDIUM
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enabled_languages][fr] (or any other language) parameter to wp-adm
Jan 12, 20184.817NONO
CVE-2018-5362MEDIUM
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][page] parameter to wp-admin/options.php.
Jan 12, 20184.817NONO
CVE-2018-5367MEDIUM
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][post] parameter to wp-admin/options.php.
Jan 12, 20184.816NONO
CVE-2018-5365MEDIUM
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[selector_wp_list_pages][show_selector] parameter to wp-admin/options.php.
Jan 12, 20184.816NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
88%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required8 (100.0%)
Privileges Required
Low0 (0.0%)
High6 (75.0%)
None2 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpglobus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpglobus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpglobus's Products

View all 2 CNAs →

Top CWEs