Wpindeed develops a small set of WordPress-oriented plugins and tools, including Debug Assistant, Ultimate Membership Pro, and Ultimate Learning Pro, that extend authentication and content management capabilities for WordPress sites. The observed vulnerability profile concentrates on application-layer weaknesses typical of web plugins—including cross-site request forgery, improper input validation, cross-site scripting, SQL injection, and untrusted deserialization—reflecting the inherent attack surface of server-side code that processes user input and manages authentication state. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpindeed over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43242CRITICAL Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | Aug 19, 2024 | 10.0 | 30 | NO | NO |
CVE-2024-43240CRITICAL Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | Aug 19, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-26516HIGH Cross-Site Request Forgery (CSRF) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions. | Nov 13, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-13846MEDIUM The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parameter in all versions up to, and including, 3.9 due to insuffi | Feb 21, 2025 | 4.9 | 17 | NO | NO |
CVE-2023-26527MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions. | Jun 16, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpindeed.
Media articles that mention a CVE ID that affects a product developed by Wpindeed — matched by CVE ID, not by vendor name.