WP White Security develops WordPress security and monitoring plugins, with a focused product portfolio that includes activity logging, two-factor authentication, CAPTCHA, and file-change detection components widely used across WordPress installations. Vulnerabilities affecting the vendor recur through web-application weakness classes including CSRF, missing and bypassable authorization controls, path traversal, and cross-site scripting, reflecting the plugin-integration context and user-input handling demands of the WordPress ecosystem. Defenders should prioritize timely plugin updates and restrict administrative access; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpwhitesecurity over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2184HIGH The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-S | Aug 1, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-2269CRITICAL The Website File Changes Monitor WordPress plugin before 1.8.3 does not sanitise and escape user input before using it in a SQL statement via an action available to users with the | Aug 8, 2022 | 9.8 | 24 | NO | NO |
CVE-2022-2891MEDIUM The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes | Oct 10, 2022 | 5.9 | 22 | NO | NO |
CVE-2020-36716HIGH The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the setup_page function in versions up to, and including, 4.0.1. | Jun 7, 2023 | 7.3 | 21 | NO | NO |
CVE-2023-2286MEDIUM The WP Activity Log for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.0. This is due to missing or incorrect nonce validation on the a | Jun 9, 2023 | 4.3 | 18 | NO | NO |
CVE-2022-1527MEDIUM The WP 2FA WordPress plugin before 2.2.1 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | May 30, 2022 | 6.1 | 18 | NO | NO |
CVE-2023-2261MEDIUM The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_ajax_call function in versions up to, and including, | Jun 9, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-2285MEDIUM The WP Activity Log Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.0. This is due to missing or incorrect nonce vali | Jun 9, 2023 | 4.3 | 16 | NO | NO |
CVE-2023-6506MEDIUM The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.0 via the send | Jan 11, 2024 | 4.3 | 15 | NO | NO |
CVE-2023-2284MEDIUM The WP Activity Log Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_switch_db function in versions up | Jun 9, 2023 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpwhitesecurity.
Media articles that mention a CVE ID that affects a product developed by Wpwhitesecurity — matched by CVE ID, not by vendor name.