Wpplugin develops a series of WordPress plugins focused on e-commerce and form functionality, particularly payment-processing and donation-collection add-ons that extend popular platforms like Contact Form 7. The vendor's vulnerability profile centers on web-application input-handling and request-validation weaknesses, including cross-site request forgery, cross-site scripting, and code injection flaws that are characteristic of plugins operating at the form and payment boundary. A moderate tendency toward public exploit availability reflects the accessibility and appeal of WordPress plugins as targets; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpplugin over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9593HIGH The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time C | Oct 18, 2024 | 8.3 | 43 | NO | YES |
CVE-2023-24405HIGH Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on plugin <= 1.9.3 versions. | Jul 10, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-24395HIGH Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 Redirect & Thank You Page plugin <= 1.0.3 versions. | Jul 10, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-51683HIGH Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now Button: from n/a through 1.8.1 | Feb 28, 2024 | 8.8 | 23 | NO | NO |
CVE-2021-24989MEDIUM The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing att | Jan 24, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-4628MEDIUM The Easy PayPal Buy Now Button WordPress plugin before 1.7.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shor | Feb 13, 2023 | 5.4 | 20 | NO | NO |
CVE-2024-10685MEDIUM The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.0. | Nov 12, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-10683MEDIUM The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropri | Nov 9, 2024 | 6.1 | 19 | NO | NO |
CVE-2021-24815MEDIUM The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cr | Nov 17, 2021 | 4.8 | 19 | NO | NO |
CVE-2025-47517MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Stored XSS.This issue affects Accept Donations w | May 7, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpplugin.
Media articles that mention a CVE ID that affects a product developed by Wpplugin — matched by CVE ID, not by vendor name.