Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpwebelite

First CVE: Jun 15, 2024Active for: 2 yearsTotal CVEs: 18
40.5
VTI Score
High

Wpwebelite develops WordPress plugins and extensions focused on e-commerce and content-engagement functionality, with a modest but prominent footprint around WooCommerce social login, PDF vouchers, and blog-tracking tools. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through access-control weaknesses including missing authorization, authentication bypass, unsafe deserialization, and cross-site scripting, reflecting the trust-boundary and user-input handling demands of plugins that integrate with WordPress. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpwebelite over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 15, 2024
2 years ago
Most Recent CVE
Jan 5, 2026
200 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-43132CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / Watchlist) allows SQL
Aug 29, 20249.830NONO
CVE-2024-7503CRITICAL
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of th
Aug 12, 20249.828NONO
CVE-2024-6636CRITICAL
The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in al
Jul 20, 20249.828NONO
CVE-2024-5871CRITICAL
The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from th
Jun 15, 20249.827NONO
CVE-2024-54383CRITICAL
Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege Escalation.This issue affects WooCommerce PDF Vouchers: fro
Dec 18, 20249.826NONO
CVE-2024-39650CRITICAL
Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WooCommerce PDF Vouch
Nov 1, 20249.826NONO
CVE-2024-39651CRITICAL
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vouchers allows File Manipulation.This issue affects WooCommer
Aug 13, 20249.326NONO
CVE-2025-64258HIGH
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Retrieve Embedded Sensitive Data.Th
Dec 18, 20257.524NONO
CVE-2024-10114HIGH
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on
Nov 5, 20248.124NONO
CVE-2025-39472HIGH
Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: fr
Apr 16, 20258.823NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
17%
44%
39%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (88.9%)
High2 (11.1%)
Unknown0 (0.0%)
User Interaction
None15 (83.3%)
Unknown0 (0.0%)
Required3 (16.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None18 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpwebelite.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpwebelite — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpwebelite's Products

View all 2 CNAs →

Top CWEs