Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpmet

First CVE: May 5, 2021Active for: 5 yearsTotal CVEs: 67
27.3
VTI Score
Low

Wpmet develops a modestly sized but widely deployed family of WordPress plugins focused on page-building and form-generation capabilities, primarily through Elementor integrations such as MetForm, ElementsKit, and WP Ultimate Review. Vulnerabilities affecting the vendor cluster around application-layer input-handling and authorization concerns—cross-site scripting, missing or bypassable authorization checks, and cross-site request forgery—that are characteristic of plugins operating in shared WordPress environments where user roles and content boundaries matter significantly. A meaningful share of the vendor's disclosures reach serious severity, and the recurring patterns suggest that defenders should prioritize authorization and input-validation patches for these plugins, particularly in multi-user or community-driven WordPress installations. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
67
Total CVEs
More Total CVEs than 99% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpmet over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2021
5 years ago
Most Recent CVE
Jul 24, 2025
365 days ago

Products(9 total)

Top CVEs

Signals from CVEs in this vendor scope (67 CVEs).

67 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-0084MEDIUM
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to
Mar 2, 20236.139NOYES
CVE-2022-0788CRITICAL
The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST
Jun 8, 20229.837NOYES
CVE-2022-1442HIGH
The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unaut
May 10, 20227.532NOYES
CVE-2023-0714CRITICAL
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions up to, and including, 3.2.4. Th
Aug 17, 20249.828NONO
CVE-2024-4404CRITICAL
The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' function. This can allow authenti
Jun 14, 20249.627NONO
CVE-2023-50903CRITICAL
Missing Authorization vulnerability in Roxnor Metform metform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Metform: from n/a through <
Dec 9, 20249.826NONO
CVE-2024-6698HIGH
The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta up
Aug 1, 20248.826NONO
CVE-2024-3500HIGH
The ElementsKit Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.0 via the Price Menu, Hotspot, and Advanced Toggle widgets.
May 2, 20248.826NONO
CVE-2024-2047HIGH
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the render_raw function. This makes it p
Mar 30, 20248.825NONO
CVE-2023-46085HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions.
Oct 22, 20238.825NONO
View all 67 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products67 CVEs
73%
21%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.5%)
Network66 (98.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low67 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None32 (47.8%)
Unknown0 (0.0%)
Required35 (52.2%)
Privileges Required
Low41 (61.2%)
High2 (3.0%)
None24 (35.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (67 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
3.0% of CVEs· 95th percentile
ExploitDB
1 CVE
1.5% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpmet.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpmet — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpmet's Products

View all 3 CNAs →

Top CWEs