Wpserveur develops a modest portfolio of WordPress-focused plugins and tools, including user-authentication and theme-generation products that sit within widely deployed content-management environments. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, while the recurring weakness classes—improper authentication, authorization bypass, cross-site request forgery, and path traversal—reflect the attack surface inherent to server-side WordPress extensions handling user sessions and file access. Defenders should prioritize patching for these plugins in production WordPress instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpserveur over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24917HIGH The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.ph | Dec 6, 2021 | 7.5 | 81 | NO | YES |
CVE-2019-15823CRITICAL The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass. | Aug 30, 2019 | 9.8 | 43 | NO | YES |
CVE-2019-15826CRITICAL The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field. | Aug 30, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-15825CRITICAL The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass. | Aug 30, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-15824CRITICAL The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass. | Aug 30, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-15822CRITICAL The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal. | Aug 30, 2019 | 9.8 | 29 | NO | NO |
CVE-2024-6289MEDIUM The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to ac | Jul 15, 2024 | 6.1 | 28 | NO | YES |
CVE-2024-2473MEDIUM The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'act | Jun 11, 2024 | 5.3 | 27 | NO | YES |
CVE-2020-36710HIGH The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenti | Jun 7, 2023 | 7.5 | 22 | NO | NO |
CVE-2015-9498HIGH The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value. | Oct 22, 2019 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpserveur.
Media articles that mention a CVE ID that affects a product developed by Wpserveur — matched by CVE ID, not by vendor name.