Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpvibes

First CVE: Nov 8, 2021Active for: 5 yearsTotal CVEs: 15
35.9
VTI Score
Medium

Wpvibes develops a portfolio of WordPress plugins spanning email logging, form handling, redirects, and page-builder integration that reflect common WordPress site administration and user-engagement functions. The vendor's vulnerability profile concentrates on application-layer input-handling and access-control weaknesses, including SQL injection, cross-site scripting, CSRF, unrestricted file uploads, and path traversal, which are characteristic of plugin-based WordPress extensions. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpvibes over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2021
4 years ago
Most Recent CVE
Jun 11, 2026
42 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-5674HIGH
The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users
Dec 26, 20238.829NONO
CVE-2023-33999HIGH
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: fro
Jun 11, 20267.127NONO
CVE-2023-5645HIGH
The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users
Dec 26, 20238.827NONO
CVE-2022-45807HIGH
Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions.
Feb 2, 20238.827NONO
CVE-2023-5673HIGH
The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to rem
Dec 26, 20238.825NONO
CVE-2023-51410HIGH
Unrestricted Upload of File with Dangerous Type vulnerability in WPVibes WP Mail Log.This issue affects WP Mail Log: from n/a through 1.1.2.
Dec 29, 20238.824NONO
CVE-2022-3764HIGH
The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.
Jan 16, 20247.223NONO
CVE-2023-5672MEDIUM
The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attac
Dec 26, 20236.522NONO
CVE-2023-5644HIGH
The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only
Dec 26, 20237.622NONO
CVE-2024-5325MEDIUM
The Form Vibes plugin for WordPress is vulnerable to SQL Injection via the ‘fv_export_data’ parameter in all versions up to, and including, 1.4.10 due to insufficient escaping on t
Jul 12, 20246.521NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
40%
60%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (73.3%)
Unknown0 (0.0%)
Required4 (26.7%)
Privileges Required
Low8 (53.3%)
High2 (13.3%)
None5 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpvibes.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpvibes — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpvibes's Products

View all 3 CNAs →

Top CWEs