SecAlerts
w

wpmet

Security Risk Profile

27
/100
low

Security Risk Score

Comprehensive risk assessment based on 70 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from May 5, 2021 to present

70
Total CVEs
19
Critical+High
0
Exploited
6
Unpatched

Threat Assessment

Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
6
Critical/High
Risk Level
27/100
low

Severity Distribution

Critical
4
High
15
Medium
51
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
20

Age Distribution

Common Weaknesses (CWE)

1
XSS
28
2
CSRF
6
3
Infoleak
4
4
Path Traversal
1
5
Malicious File Upload
1

Most Affected Products

1. Wpmet Metform Elementor Contact Form Builder Wordpress24
2. Wpmet Elements Kit Elementor Addons Wordpress13
3. Wpmet Elementskit Wordpress9
4. Wpmet Elementskit Elementor Addons Wordpress7
5. Wpmet Wp Ultimate Review Wordpress7

Recent Vulnerabilities

See more →
CVE-2026-49053
CVSS 5.3medium

WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulnerability

May 27, 2026🔧 No Patch
CVE-2026-49052
CVSS 4.3medium

WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulnerability

May 27, 2026🔧 No Patch
CVE-2025-3614
CVSS 6.4medium

ElementsKit Elementor Addons and Templates <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget

Jul 24, 2025🔧 No Patch
CVE-2025-4479
CVSS 6.4medium

ElementsKit Lite <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget

Jun 19, 2025
CVE-2025-46253
CVSS 6.5EPSS 0%medium

WordPress GutenKit plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability

Apr 22, 2025
CVE-2024-11180
CVSS 6.4medium

ElementsKit Elementor addons <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 29, 2025
CVE-2025-1506
CVSS 4.3medium

Wp Social Login and Register Social Counter <= 3.1.0 - Cross-Site Request Forgery to Settings Update

Feb 28, 2025
CVE-2025-0968
CVSS 5.3medium

ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function

Feb 19, 2025
CVE-2025-1005
CVSS 6.4medium

ElementsKit Elementor addons <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget

Feb 15, 2025
CVE-2025-0321
CVSS 6.4medium

ElementsKit Pro <= 3.7.8 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via url Parameter

Jan 28, 2025🔧 No Patch

Monitor wpmet in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

wpmet Security Vulnerabilities & Risk Score | 70 CVEs | SecAlerts - SecAlerts