Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpwebinfotech

First CVE: Jul 24, 2024Active for: 2 yearsTotal CVEs: 9

Wpwebinfotech develops WordPress plugins and web-facing tools, with its Social Auto Poster plugin serving as a focal point for vulnerability reports; the vendor's disclosures center on web-application input-handling and authorization weaknesses typical of content-management ecosystem extensions. Vulnerabilities affecting this vendor frequently acquire public exploit code, and the recurring weakness classes—cross-site scripting, missing authorization, CSRF, and unrestricted file uploads—reflect common attack vectors in plugin development where sanitization and access control boundaries are often underspecified. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
9.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpwebinfotech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 24, 2024
23 months ago
Most Recent CVE
Oct 20, 2024
642 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-6753MEDIUM
The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function
Jul 24, 20246.128NOYES
CVE-2024-6756HIGH
The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all vers
Jul 24, 20248.826NONO
CVE-2024-49272HIGH
Cross-Site Request Forgery (CSRF) vulnerability in wpweb Social Auto Poster social-auto-poster allows Cross Site Request Forgery.This issue affects Social Auto Poster: from n/a thr
Oct 20, 20248.824NONO
CVE-2024-6750HIGH
The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all vers
Jul 24, 20247.522NONO
CVE-2024-47369MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweb Social Auto Poster social-auto-poster allows Reflected XSS.This issue af
Oct 5, 20246.119NONO
CVE-2024-6751MEDIUM
The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing or incorrect nonce validati
Jul 24, 20246.519NONO
CVE-2024-6755MEDIUM
The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_multi
Jul 24, 20245.318NONO
CVE-2024-6752MEDIUM
The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function
Jul 24, 20245.417NONO
CVE-2024-6754MEDIUM
The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function
Jul 24, 20244.315NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
67%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (44.4%)
Unknown0 (0.0%)
Required5 (55.6%)
Privileges Required
Low3 (33.3%)
High0 (0.0%)
None6 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpwebinfotech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpwebinfotech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpwebinfotech's Products

View all 2 CNAs →

Top CWEs