WP Manage Ninja develops a focused suite of WordPress plugins spanning tables, support ticketing, email delivery, CRM, and authentication functionality, products that collectively reach a modestly represented but above-typical share of vulnerable WordPress infrastructure. The vendor's vulnerability profile centers consistently on application-layer input-handling and access-control issues: cross-site scripting and SQL injection across form inputs, missing authorization checks in administrative and user-facing endpoints, server-side request forgery in integrations, and authentication-bypass flaws in credential-handling logic. These weakness classes reflect the characteristic risks of WordPress plugin development, where rapid iteration, plugin interdependencies, and direct database access amplify both the likelihood of input-validation gaps and the impact of authorization failures on multi-tenant hosting environments. Defenders deploying these plugins should prioritize patching cycles, audit form handlers and administrative endpoints for access controls, and restrict plugin administrative capabilities through WordPress role management. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpmanageninja over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2544HIGH The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which a | Aug 22, 2022 | 7.5 | 36 | NO | YES |
CVE-2026-57715HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinja Fluent CRM fluent-crm allows Reflected XSS.This issue affects Fl | Jul 13, 2026 | 7.1 | 33 | NO | NO |
CVE-2026-65470MEDIUM Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions. | Jul 23, 2026 | 6.5 | 27 | NO | NO |
CVE-2024-47302CRITICAL Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flue | Nov 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2026-65474MEDIUM Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. | Jul 23, 2026 | 5.3 | 25 | NO | NO |
CVE-2024-47304HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Fluent Support fluent-support allows SQL Injection.This issue | Oct 17, 2024 | 8.5 | 24 | NO | NO |
CVE-2022-4746HIGH The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-b | Jan 23, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-2559HIGH The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injecti | Aug 29, 2022 | 7.2 | 24 | NO | NO |
CVE-2025-2940HIGH The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.18 via the args[url] paramete | Jun 27, 2025 | 7.2 | 22 | NO | NO |
CVE-2024-13568HIGH The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via | Mar 1, 2025 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpmanageninja.
Media articles that mention a CVE ID that affects a product developed by Wpmanageninja — matched by CVE ID, not by vendor name.