SecAlerts
w

wpzoom

Security Risk Profile

29
/100
low

Security Risk Score

Comprehensive risk assessment based on 28 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from September 27, 2021 to present

28
Total CVEs
4
Critical+High
0
Exploited
1
Unpatched

Threat Assessment

Avg CVSS
6.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
29/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
1
High
3
Medium
24
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
10

Age Distribution

Common Weaknesses (CWE)

1
XSS
19
2
Path Traversal
2
3
Infoleak
1

Most Affected Products

1. WPZOOM Beaver Builder Addons Wordpress7
2. WPZOOM Recipe Card Blocks For Gutenberg \& Elementor Wordpress3
3. WPZOOM Wpzoom Elementor Addons Wordpress3
4. WPZOOM Wpzoom Shortcodes Wordpress2
5. WPZOOM WPZOOM Portfolio WordPress2

Recent Vulnerabilities

See more →
CVE-2026-100149
CVSS 5.3medium

WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons <= 4.7.3 - Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`…

Oct 3, 2026🔧 No Patch
CVE-2026-3011
CVSS 6.4medium

Recipe Card Blocks Lite <= 3.4.13 - Authenticated (Author+) Stored Cross-Site Scripting via 'summary' and 'notes'

Jun 8, 2026🔧 No Patch
CVE-2026-4063
CVSS 4.3EPSS 0%medium

Social Icons Widget & Block <= 4.5.8 - Missing Authorization to Authenticated (Subscriber+) Sharing Configuration Creation

Mar 13, 2026🔧 No Patch
CVE-2025-62019
CVSS 6.5medium

WordPress Recipe Card Blocks for Gutenberg & Elementor plugin <= 3.4.8 - Broken Access Control vulnerability

Oct 22, 2025🔧 No Patch
CVE-2025-26983
CVSS 4.3EPSS 0%medium

WordPress Recipe Card Blocks for Gutenberg & Elementor plugin <= 3.4.3 - Broken Access Control vulnerability

Feb 25, 2025🔧 No Patch
CVE-2024-30424
CVSS 6.5medium

WordPress Beaver Builder Addons by WPZOOM plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability

Nov 19, 2024
CVE-2024-43293
CVSS 8.8high

WordPress Recipe Card Blocks for Gutenberg & Elementor plugin <= 3.3.1 - Broken Access Control vulnerability

Nov 1, 2024
CVE-2024-9027
CVSS 6.4EPSS 0%medium

WPZOOM Shortcodes <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via box Shortcode

Sep 25, 2024🔧 No Patch
CVE-2024-8276
CVSS 6.4EPSS 0%medium

WPZOOM Portfolio Lite – Filterable Portfolio Plugin <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute

Aug 31, 2024
CVE-2024-37464
CVSS 4.9medium

WordPress Beaver Builder Addons by WPZOOM plugin <= 1.3.5 - Local File Inclusion vulnerability

Jul 9, 2024

Monitor wpzoom in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

wpzoom Security Vulnerabilities & Risk Score | 28 CVEs | SecAlerts - SecAlerts