Wpwebelite develops WordPress plugins and extensions focused on e-commerce and content-engagement functionality, with a modest but prominent footprint around WooCommerce social login, PDF vouchers, and blog-tracking tools. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through access-control weaknesses including missing authorization, authentication bypass, unsafe deserialization, and cross-site scripting, reflecting the trust-boundary and user-input handling demands of plugins that integrate with WordPress. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpwebelite over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43132CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / Watchlist) allows SQL | Aug 29, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-7503CRITICAL The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of th | Aug 12, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-6636CRITICAL The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in al | Jul 20, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-5871CRITICAL The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from th | Jun 15, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-54383CRITICAL Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege Escalation.This issue affects WooCommerce PDF Vouchers: fro | Dec 18, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-39650CRITICAL Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WooCommerce PDF Vouch | Nov 1, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-39651CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vouchers allows File Manipulation.This issue affects WooCommer | Aug 13, 2024 | 9.3 | 26 | NO | NO |
CVE-2025-64258HIGH Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Retrieve Embedded Sensitive Data.Th | Dec 18, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-10114HIGH The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on | Nov 5, 2024 | 8.1 | 24 | NO | NO |
CVE-2025-39472HIGH Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: fr | Apr 16, 2025 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpwebelite.
Media articles that mention a CVE ID that affects a product developed by Wpwebelite — matched by CVE ID, not by vendor name.