Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpindeed

First CVE: Jun 16, 2023Active for: 3 yearsTotal CVEs: 5

Wpindeed develops a small set of WordPress-oriented plugins and tools, including Debug Assistant, Ultimate Membership Pro, and Ultimate Learning Pro, that extend authentication and content management capabilities for WordPress sites. The observed vulnerability profile concentrates on application-layer weaknesses typical of web plugins—including cross-site request forgery, improper input validation, cross-site scripting, SQL injection, and untrusted deserialization—reflecting the inherent attack surface of server-side code that processes user input and manages authentication state. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpindeed over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2023
3 years ago
Most Recent CVE
Feb 21, 2025
518 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-43242CRITICAL
Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
Aug 19, 202410.030NONO
CVE-2024-43240CRITICAL
Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
Aug 19, 20249.829NONO
CVE-2023-26516HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions.
Nov 13, 20238.824NONO
CVE-2024-13846MEDIUM
The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parameter in all versions up to, and including, 3.9 due to insuffi
Feb 21, 20254.917NONO
CVE-2023-26527MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions.
Jun 16, 20234.816NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
40%
20%
40%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (60.0%)
Unknown0 (0.0%)
Required2 (40.0%)
Privileges Required
Low0 (0.0%)
High2 (40.0%)
None3 (60.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpindeed.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpindeed — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpindeed's Products

View all 2 CNAs →

Top CWEs