SecAlerts
w

wpdeveloper

Security Risk Profile

39
/100
low

Security Risk Score

Comprehensive risk assessment based on 153 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 12, 2019 to present

153
Total CVEs
43
Critical+High
0
Exploited
19
Unpatched

Threat Assessment

Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
19
Critical/High
Risk Level
39/100
low
📈 2 in Last 30 Days

Severity Distribution

Critical
12
High
31
Medium
109
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
1
<5%
53

Age Distribution

Common Weaknesses (CWE)

1
XSS
83
2
Infoleak
6
3
CSRF
5
4
SQL Injection
4
5
Path Traversal
4

Most Affected Products

1. WPDeveloper Essential Addons For Elementor Wordpress55
2. WPDeveloper Embedpress Wordpress25
3. WPDeveloper Essential Blocks Wordpress23
4. WPDeveloper Essential Addons for Elementor10
5. WPDeveloper Reviewx Wordpress8

Recent Vulnerabilities

See more →
CVE-2026-102394
CVSS 6.5medium

WordPress Essential Addons for Elementor plugin <= 6.8.4 - Cross Site Scripting (XSS) vulnerability

Oct 1, 2026🔧 No Patch
CVE-2026-96256
CVSS 6.4medium

Gutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute

Oct 1, 2026🔧 No Patch
CVE-2026-81777
CVSS 5.3medium

WordPress Essential Addons for Elementor plugin <= 6.8.0 - Bypass vulnerability vulnerability

Aug 28, 2026🔧 No Patch
CVE-2026-57364
CVSS 6.5medium

WordPress Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More plugin <= 2.2.0 - Other Vulnerability Type vulnerability

Jul 13, 2026🔧 No Patch
CVE-2026-10833
CVSS 6.4medium

Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute

Jun 25, 2026🔧 No Patch
CVE-2026-12157
CVSS 6.4medium

BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute

Jun 19, 2026🔧 No Patch
CVE-2026-40721
CVSS 7.5high

WordPress Element Pack Pro plugin <= 9.0.6 - Local File Inclusion vulnerability

Jun 17, 2026🔧 No Patch
CVE-2026-9243
CVSS 6.4EPSS 0%medium

The Plus Addons for Elementor <= 6.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' Parameter

May 29, 2026🔧 No Patch
CVE-2026-4658
CVSS 6.4medium

Gutenberg Essential Blocks <= 6.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes

May 2, 2026🔧 No Patch
CVE-2026-42644
CVSS 5.3medium

WordPress BetterDocs plugin <= 4.3.10 - Sensitive Data Exposure vulnerability

Apr 29, 2026🔧 No Patch

Monitor wpdeveloper in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

wpdeveloper Security Vulnerabilities & Risk Score | 153 CVEs | SecAlerts - SecAlerts