Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpmudev

First CVE: Oct 6, 2017Active for: 9 yearsTotal CVEs: 33
23.9
VTI Score
Low

Wpmudev is a specialist WordPress plugin vendor whose vulnerability footprint centers on a modestly sized but widely adopted suite of site management, security, and optimization tools including Forminator Forms, Defender, Branda, and Broken Link Checker. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the web-facing and administrative roles these plugins occupy within WordPress installations. The recurring weakness classes—cross-site scripting, cross-site request forgery, missing authorization, and authentication bypass—are characteristic of plugin-layer access control and input-handling challenges in WordPress ecosystem software. Defenders should track Wpmudev's updates for plugins deployed across their managed WordPress infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 98% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpmudev over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2017
8 years ago
Most Recent CVE
May 12, 2026
75 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-20206CRITICAL
The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the `wpmudev_appoint
Oct 18, 20259.834NONO
CVE-2022-44581CRITICAL
Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files for Sensitive Information.This issue affects Defender Security
May 17, 20249.829NONO
CVE-2023-47189CRITICAL
Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a t
Jun 4, 20249.828NONO
CVE-2023-5089MEDIUM
The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to ac
Oct 16, 20235.328NOYES
CVE-2024-37444CRITICAL
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Defender Security defender-security.This issue affects Defender Security: from n/a through <= 4
Nov 1, 20249.826NONO
CVE-2024-10402HIGH
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in
Oct 26, 20248.825NONO
CVE-2024-43117HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a throug
Aug 26, 20248.824NONO
CVE-2017-18510HIGH
The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions.
Aug 14, 20198.824NONO
CVE-2017-15079HIGH
The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal.
Oct 6, 20177.524NONO
CVE-2024-0368HIGH
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via h
Mar 13, 20248.623NONO
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
64%
24%
12%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network33 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (51.5%)
Unknown0 (0.0%)
Required16 (48.5%)
Privileges Required
Low5 (15.2%)
High4 (12.1%)
None24 (72.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.0% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpmudev.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpmudev — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpmudev's Products

View all 5 CNAs →

Top CWEs