Wpruby develops administrative access-control and help-desk management solutions, with a vulnerability profile centered on authorization and access-control weaknesses including improper access control, authorization bypass through user-controlled keys, and direct-request vulnerabilities. These patterns reflect the sensitive nature of administrative interfaces and the authentication-enforcement demands of help-desk platforms; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpruby over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24215CRITICAL An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality | Apr 12, 2021 | 9.8 | 45 | NO | YES |
CVE-2021-4360HIGH The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configurati | Jun 7, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-1125MEDIUM The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add fil | May 2, 2023 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpruby.
Media articles that mention a CVE ID that affects a product developed by Wpruby — matched by CVE ID, not by vendor name.