Wpmet develops a modestly sized but widely deployed family of WordPress plugins focused on page-building and form-generation capabilities, primarily through Elementor integrations such as MetForm, ElementsKit, and WP Ultimate Review. Vulnerabilities affecting the vendor cluster around application-layer input-handling and authorization concerns—cross-site scripting, missing or bypassable authorization checks, and cross-site request forgery—that are characteristic of plugins operating in shared WordPress environments where user roles and content boundaries matter significantly. A meaningful share of the vendor's disclosures reach serious severity, and the recurring patterns suggest that defenders should prioritize authorization and input-validation patches for these plugins, particularly in multi-user or community-driven WordPress installations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpmet over time
Signals from CVEs in this vendor scope (67 CVEs).
67 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0084MEDIUM The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to | Mar 2, 2023 | 6.1 | 39 | NO | YES |
CVE-2022-0788CRITICAL The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST | Jun 8, 2022 | 9.8 | 37 | NO | YES |
CVE-2022-1442HIGH The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unaut | May 10, 2022 | 7.5 | 32 | NO | YES |
CVE-2023-0714CRITICAL The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions up to, and including, 3.2.4. Th | Aug 17, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-4404CRITICAL The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' function. This can allow authenti | Jun 14, 2024 | 9.6 | 27 | NO | NO |
CVE-2023-50903CRITICAL Missing Authorization vulnerability in Roxnor Metform metform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Metform: from n/a through < | Dec 9, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-6698HIGH The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta up | Aug 1, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-3500HIGH The ElementsKit Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.0 via the Price Menu, Hotspot, and Advanced Toggle widgets. | May 2, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-2047HIGH The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the render_raw function. This makes it p | Mar 30, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-46085HIGH Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions. | Oct 22, 2023 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (67 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpmet.
Media articles that mention a CVE ID that affects a product developed by Wpmet — matched by CVE ID, not by vendor name.