Wpkube develops a focused collection of WordPress plugins and extensions including social sharing, contact forms, comment subscriptions, and author display tools that are distributed across WordPress installations. Its vulnerabilities skew toward serious outcomes and center on application-layer flaws endemic to web plugins: cross-site scripting, cross-site request forgery, sensitive information exposure, and improper logging practices. Defenders should treat WordPress plugin updates from this vendor as a security priority given the ease of automated scanning and deployment across diverse WordPress environments; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpkube over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4362CRITICAL The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiw | Jun 7, 2023 | 9.8 | 30 | NO | NO |
CVE-2025-13614HIGH The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' shortcode in all versions up to, and including, 2.29 due to i | Dec 5, 2025 | 8.1 | 28 | NO | NO |
CVE-2026-4409MEDIUM The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a weak hash generation algorithm | May 5, 2026 | 6.5 | 26 | NO | NO |
CVE-2025-12010MEDIUM The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method call from Authors_L | Nov 11, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-69011MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Cool Tag Cloud cool-tag-cloud allows Stored XSS.This issue affects Cool | Feb 20, 2026 | 6.5 | 21 | NO | NO |
CVE-2024-31249HIGH Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725. | Apr 10, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-13806MEDIUM The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.6. This is due to the software allowing users to | Mar 1, 2025 | 6.5 | 20 | NO | NO |
CVE-2022-29414MEDIUM Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, | Apr 29, 2022 | 5.4 | 20 | NO | NO |
CVE-2021-24745MEDIUM The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before outputting them in attributes, which could allow user with a | Nov 29, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-24682MEDIUM The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, which could allow users with a role as low as Contributor to pe | Nov 1, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpkube.
Media articles that mention a CVE ID that affects a product developed by Wpkube — matched by CVE ID, not by vendor name.