Wplab develops a focused line of WordPress plugins designed to integrate with e-commerce marketplaces, specifically listing and inventory-management tools for Amazon and eBay. The recurring vulnerability signal centers on cross-site scripting weaknesses in web-page generation, a pattern typical of plugin-based content handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wplab over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-37261MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Li | Jul 22, 2024 | 6.1 | 27 | NO | YES |
CVE-2024-32836CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This issue affects WP-Lister Lite for eBay: from n/a through <= 3 | Apr 24, 2024 | 9.1 | 25 | NO | NO |
CVE-2024-47380HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay allows Reflected XSS.This is | Oct 5, 2024 | 7.1 | 21 | NO | NO |
CVE-2024-43306MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This issue affects WP-Lister | Aug 18, 2024 | 6.5 | 20 | NO | NO |
CVE-2026-25384MEDIUM Missing Authorization vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects | Feb 19, 2026 | 5.3 | 19 | NO | NO |
CVE-2024-32573MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This issue affects WP-Lister | Apr 18, 2024 | 5.9 | 18 | NO | NO |
CVE-2024-30199HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Li | Mar 27, 2024 | 7.1 | 18 | NO | NO |
CVE-2024-2889MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Li | Mar 26, 2024 | 5.9 | 18 | NO | NO |
CVE-2024-22307MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This issue affects WP-Lister | Jan 31, 2024 | 6.1 | 18 | NO | NO |
CVE-2025-62881MEDIUM Missing Authorization vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects | Oct 27, 2025 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wplab.
Media articles that mention a CVE ID that affects a product developed by Wplab — matched by CVE ID, not by vendor name.