SecAlerts
wpfactory logo

wpfactory

Security Risk Profile

40
/100
medium

Security Risk Score

Comprehensive risk assessment based on 51 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from October 7, 2019 to present

51
Total CVEs
14
Critical+High
0
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
40/100
medium

Severity Distribution

Critical
4
High
10
Medium
37
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
21

Age Distribution

Common Weaknesses (CWE)

1
XSS
32
2
CSRF
5
3
Code Injection
1
4
SQL Injection
1
5
Infoleak
1

Most Affected Products

1. WPFactory Ean For Woocommerce Wordpress4
2. WPFactory EAN for WooCommerce3
3. WPFactory Eu\/uk Vat Manager For Woocommerce Wordpress3
4. WPFactory Products\, Order \& Customers Export For Woocommerce Wordpress3
5. WPFactory Helpdesk Support Ticket System for WooCommerce2

Recent Vulnerabilities

See more →
CVE-2026-23977
CVSS 7.5high

WordPress Helpdesk Support Ticket System for WooCommerce plugin <= 2.1.2 - Broken Access Control vulnerability

3/25/2026🔧 No Patch
CVE-2025-62096
CVSS 6.5medium

WordPress Maximum Products per User for WooCommerce plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability

12/31/2025🔧 No Patch
CVE-2025-57911
CVSS 6.5medium

WordPress Adverts Plugin <= 1.4 - Cross Site Scripting (XSS) Vulnerability

9/22/2025🔧 No Patch
CVE-2025-57972
CVSS 4.3medium

WordPress Helpdesk Support Ticket System for WooCommerce plugin <= 2.1.1 - Broken Access Control vulnerability

9/22/2025🔧 No Patch
CVE-2025-58985
CVSS 6.5medium

WordPress Additional Custom Product Tabs for WooCommerce Plugin <= 1.7.3 - Cross Site Scripting (XSS) Vulnerability

9/9/2025
CVE-2025-49887
CVSS 9.9critical

WordPress Product XML Feed Manager for WooCommerce Plugin <= 2.9.3 - Remote Code Execution (RCE) Vulnerability

8/14/2025
CVE-2025-49987
CVSS 5.3medium

WordPress CRM ERP Business Solution plugin <= 1.13 - Broken Access Control Vulnerability

6/20/2025🔧 No Patch
CVE-2025-49510
CVSS 4.3EPSS 0%medium

WordPress Min Max Step Quantity Limits Manager for WooCommerce plugin <= 5.1.0 - Cross Site Request Forgery (CSRF) vulnerability

6/10/2025
CVE-2025-48253
CVSS 6.5EPSS 0%medium

WordPress Free Shipping Bar: Amount Left for Free Shipping for WooCommerce plugin <= 2.4.6 - Cross Site Scripting (XSS) Vulnerability

5/19/2025
CVE-2025-48254
CVSS 6.5EPSS 0%medium

WordPress Change Add to Cart Button Text for WooCommerce plugin <= 2.2.2 - Cross Site Scripting (XSS) Vulnerability

5/19/2025

Monitor wpfactory in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

wpfactory Security Vulnerabilities & Risk Score | 51 CVEs | SecAlerts - SecAlerts