Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpserveur

First CVE: Aug 30, 2019Active for: 7 yearsTotal CVEs: 11
63.9
VTI Score
TOP TARGET

Wpserveur develops a modest portfolio of WordPress-focused plugins and tools, including user-authentication and theme-generation products that sit within widely deployed content-management environments. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, while the recurring weakness classes—improper authentication, authorization bypass, cross-site request forgery, and path traversal—reflect the attack surface inherent to server-side WordPress extensions handling user sessions and file access. Defenders should prioritize patching for these plugins in production WordPress instances; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpserveur over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 30, 2019
6 years ago
Most Recent CVE
Jul 15, 2024
740 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24917HIGH
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.ph
Dec 6, 20217.581NOYES
CVE-2019-15823CRITICAL
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.
Aug 30, 20199.843NOYES
CVE-2019-15826CRITICAL
The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.
Aug 30, 20199.830NONO
CVE-2019-15825CRITICAL
The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.
Aug 30, 20199.829NONO
CVE-2019-15824CRITICAL
The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.
Aug 30, 20199.829NONO
CVE-2019-15822CRITICAL
The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.
Aug 30, 20199.829NONO
CVE-2024-6289MEDIUM
The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to ac
Jul 15, 20246.128NOYES
CVE-2024-2473MEDIUM
The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'act
Jun 11, 20245.327NOYES
CVE-2020-36710HIGH
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenti
Jun 7, 20237.522NONO
CVE-2015-9498HIGH
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
Oct 22, 20198.822NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
27%
27%
45%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (81.8%)
Unknown0 (0.0%)
Required2 (18.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
9.1% of CVEs· 98th percentile
Nuclei
4 CVEs
36.4% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpserveur.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpserveur — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpserveur's Products

View all 3 CNAs →

Top CWEs