SecAlerts
wpdeveloper logo

wpdeveloper

Security Risk Profile

40
/100
medium

Security Risk Score

Comprehensive risk assessment based on 150 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 12, 2019 to present

150
Total CVEs
43
Critical+High
0
Exploited
19
Unpatched

Threat Assessment

Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
19
Critical/High
Risk Level
40/100
medium
📈 1 in Last 30 Days

Severity Distribution

Critical
12
High
31
Medium
106
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
1
<5%
52

Age Distribution

Common Weaknesses (CWE)

1
XSS
81
2
Infoleak
6
3
CSRF
5
4
SQL Injection
4
5
Path Traversal
4

Most Affected Products

1. WPDeveloper Essential Addons For Elementor Wordpress55
2. WPDeveloper Embedpress Wordpress25
3. WPDeveloper Essential Blocks Wordpress23
4. WPDeveloper Essential Addons for Elementor8
5. WPDeveloper Reviewx Wordpress8

Recent Vulnerabilities

See more →
CVE-2026-57364
CVSS 6.5medium

WordPress Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More plugin <= 2.2.0 - Other Vulnerability Type vulnerability

7/13/2026🔧 No Patch
CVE-2026-10833
CVSS 6.4medium

Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute

6/25/2026🔧 No Patch
CVE-2026-12157
CVSS 6.4medium

BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute

6/19/2026🔧 No Patch
CVE-2026-40721
CVSS 7.5high

WordPress Element Pack Pro plugin <= 9.0.6 - Local File Inclusion vulnerability

6/17/2026🔧 No Patch
CVE-2026-9243
CVSS 6.4EPSS 0%medium

The Plus Addons for Elementor <= 6.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' Parameter

5/29/2026🔧 No Patch
CVE-2026-4658
CVSS 6.4medium

Gutenberg Essential Blocks <= 6.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes

5/2/2026🔧 No Patch
CVE-2026-42644
CVSS 5.3medium

WordPress BetterDocs plugin <= 4.3.10 - Sensitive Data Exposure vulnerability

4/29/2026🔧 No Patch
CVE-2026-42379
CVSS 7.7high

WordPress Templately plugin <= 3.6.1 - Sensitive Data Exposure vulnerability

4/27/2026
CVE-2026-6393
CVSS 4.3EPSS 0%medium

BetterDocs <= 4.3.11 - Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage

4/24/2026🔧 No Patch
CVE-2025-69092
CVSS 6.5medium

WordPress Essential Addons for Elementor plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability

12/30/2025🔧 No Patch

Monitor wpdeveloper in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.