Wpplugins develops a modest portfolio of WordPress plugins spanning functionality from file management to content presentation, a niche but widely installed ecosystem within WordPress deployments. Vulnerabilities affecting these plugins skew toward serious outcomes and frequently acquire public exploit code, driven by recurring input-handling and authentication weaknesses such as cross-site scripting, PHP remote file inclusion, and insufficient rate-limiting on authentication attempts that are characteristic of web-facing plugin development. Defenders tracking WordPress infrastructure should treat Wpplugins advisories as moderate priority given the plugin distribution model's reach; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpplugins over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6420HIGH The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to ac | Jul 23, 2024 | 8.6 | 34 | NO | YES |
CVE-2025-26909CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows PHP Local Fi | Mar 27, 2025 | 9.8 | 30 | NO | NO |
CVE-2005-10002CRITICAL A vulnerability, which was classified as critical, was found in almosteffortless secure-files Plugin up to 1.1 on WordPress. Affected is the function sf_downloads of the file secur | Oct 29, 2023 | 9.8 | 30 | NO | NO |
CVE-2007-10003HIGH A vulnerability, which was classified as critical, has been found in The Hackers Diet Plugin up to 0.9.6b on WordPress. This issue affects some unknown processing of the file ajax_ | Oct 29, 2023 | 8.8 | 25 | NO | NO |
CVE-2025-2056HIGH The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.4.01 via the showFile function. T | Mar 14, 2025 | 7.5 | 22 | NO | NO |
CVE-2022-4537MEDIUM The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions | May 9, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-32518MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ono Oogami WP Chinese Conversion plugin <= 1.1.16 versions. | Aug 25, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-10825MEDIUM The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up to, and including, 5.3.01 due to insu | Nov 15, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-4962MEDIUM The Video PopUp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'video_popup' shortcode in versions up to, and including, 1.1.3 due to insufficient input sani | Jan 11, 2024 | 5.4 | 18 | NO | NO |
CVE-2013-2693MEDIUM Cross-site request forgery (CSRF) vulnerability in the Options in the WP-Print plugin before 2.52 for WordPress allows remote attackers to hijack the authentication of administrato | Apr 10, 2014 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpplugins.
Media articles that mention a CVE ID that affects a product developed by Wpplugins — matched by CVE ID, not by vendor name.