Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpkube

First CVE: Nov 1, 2021Active for: 5 yearsTotal CVEs: 18
17.4
VTI Score
Low

Wpkube develops a focused collection of WordPress plugins and extensions including social sharing, contact forms, comment subscriptions, and author display tools that are distributed across WordPress installations. Its vulnerabilities skew toward serious outcomes and center on application-layer flaws endemic to web plugins: cross-site scripting, cross-site request forgery, sensitive information exposure, and improper logging practices. Defenders should treat WordPress plugin updates from this vendor as a security priority given the ease of automated scanning and deployment across diverse WordPress environments; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpkube over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 1, 2021
4 years ago
Most Recent CVE
May 5, 2026
80 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-4362CRITICAL
The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiw
Jun 7, 20239.830NONO
CVE-2025-13614HIGH
The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' shortcode in all versions up to, and including, 2.29 due to i
Dec 5, 20258.128NONO
CVE-2026-4409MEDIUM
The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a weak hash generation algorithm
May 5, 20266.526NONO
CVE-2025-12010MEDIUM
The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method call from Authors_L
Nov 11, 20256.522NONO
CVE-2025-69011MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Cool Tag Cloud cool-tag-cloud allows Stored XSS.This issue affects Cool
Feb 20, 20266.521NONO
CVE-2024-31249HIGH
Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.
Apr 10, 20247.521NONO
CVE-2024-13806MEDIUM
The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.6. This is due to the software allowing users to
Mar 1, 20256.520NONO
CVE-2022-29414MEDIUM
Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive,
Apr 29, 20225.420NONO
CVE-2021-24745MEDIUM
The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before outputting them in attributes, which could allow user with a
Nov 29, 20215.420NONO
CVE-2021-24682MEDIUM
The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, which could allow users with a role as low as Contributor to pe
Nov 1, 20215.420NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
78%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (50.0%)
Unknown0 (0.0%)
Required9 (50.0%)
Privileges Required
Low5 (27.8%)
High2 (11.1%)
None11 (61.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpkube.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpkube — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpkube's Products

View all 3 CNAs →

Top CWEs