Wpmudev is a specialist WordPress plugin vendor whose vulnerability footprint centers on a modestly sized but widely adopted suite of site management, security, and optimization tools including Forminator Forms, Defender, Branda, and Broken Link Checker. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the web-facing and administrative roles these plugins occupy within WordPress installations. The recurring weakness classes—cross-site scripting, cross-site request forgery, missing authorization, and authentication bypass—are characteristic of plugin-layer access control and input-handling challenges in WordPress ecosystem software. Defenders should track Wpmudev's updates for plugins deployed across their managed WordPress infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpmudev over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-20206CRITICAL The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the `wpmudev_appoint | Oct 18, 2025 | 9.8 | 34 | NO | NO |
CVE-2022-44581CRITICAL Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files for Sensitive Information.This issue affects Defender Security | May 17, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-47189CRITICAL Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a t | Jun 4, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-5089MEDIUM The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to ac | Oct 16, 2023 | 5.3 | 28 | NO | YES |
CVE-2024-37444CRITICAL Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Defender Security defender-security.This issue affects Defender Security: from n/a through <= 4 | Nov 1, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-10402HIGH The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in | Oct 26, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-43117HIGH Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a throug | Aug 26, 2024 | 8.8 | 24 | NO | NO |
CVE-2017-18510HIGH The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions. | Aug 14, 2019 | 8.8 | 24 | NO | NO |
CVE-2017-15079HIGH The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal. | Oct 6, 2017 | 7.5 | 24 | NO | NO |
CVE-2024-0368HIGH The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via h | Mar 13, 2024 | 8.6 | 23 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpmudev.
Media articles that mention a CVE ID that affects a product developed by Wpmudev — matched by CVE ID, not by vendor name.