Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpmanageninja

First CVE: Aug 30, 2021Active for: 5 yearsTotal CVEs: 26
28.5
VTI Score
Low

WP Manage Ninja develops a focused suite of WordPress plugins spanning tables, support ticketing, email delivery, CRM, and authentication functionality, products that collectively reach a modestly represented but above-typical share of vulnerable WordPress infrastructure. The vendor's vulnerability profile centers consistently on application-layer input-handling and access-control issues: cross-site scripting and SQL injection across form inputs, missing authorization checks in administrative and user-facing endpoints, server-side request forgery in integrations, and authentication-bypass flaws in credential-handling logic. These weakness classes reflect the characteristic risks of WordPress plugin development, where rapid iteration, plugin interdependencies, and direct database access amplify both the likelihood of input-validation gaps and the impact of authorization failures on multi-tenant hosting environments. Defenders deploying these plugins should prioritize patching cycles, audit form handlers and administrative endpoints for access controls, and restrict plugin administrative capabilities through WordPress role management. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 8% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpmanageninja over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 30, 2021
4 years ago
Most Recent CVE
Jul 23, 2026
5 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-2544HIGH
The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which a
Aug 22, 20227.536NOYES
CVE-2026-57715HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinja Fluent CRM fluent-crm allows Reflected XSS.This issue affects Fl
Jul 13, 20267.133NONO
CVE-2026-65470MEDIUM
Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
Jul 23, 20266.527NONO
CVE-2024-47302CRITICAL
Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flue
Nov 1, 20249.827NONO
CVE-2026-65474MEDIUM
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
Jul 23, 20265.325NONO
CVE-2024-47304HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Fluent Support fluent-support allows SQL Injection.This issue
Oct 17, 20248.524NONO
CVE-2022-4746HIGH
The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-b
Jan 23, 20237.524NONO
CVE-2022-2559HIGH
The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injecti
Aug 29, 20227.224NONO
CVE-2025-2940HIGH
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.18 via the args[url] paramete
Jun 27, 20257.222NONO
CVE-2024-13568HIGH
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via
Mar 1, 20257.522NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
62%
35%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (96.2%)
High1 (3.8%)
Unknown0 (0.0%)
User Interaction
None14 (53.8%)
Unknown0 (0.0%)
Required12 (46.2%)
Privileges Required
Low8 (30.8%)
High6 (23.1%)
None12 (46.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.8% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpmanageninja.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpmanageninja — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpmanageninja's Products

View all 3 CNAs →

Top CWEs