SecAlerts
wpeka logo

wpeka

Security Risk Profile

42
/100
medium

Security Risk Score

Comprehensive risk assessment based on 11 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from February 7, 2022 to present

11
Total CVEs
2
Critical+High
0
Exploited
1
Unpatched

Threat Assessment

Avg CVSS
6.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
42/100
medium

Severity Distribution

Critical
0
High
2
Medium
9
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
8
2
CSRF
1

Most Affected Products

1. WPEka Wp Cookie Consent Wordpress4
2. WPEka WP AdCenter3
3. WPEka Wp Adcenter Wordpress2
4. WP Cookie Consent WP Cookie Consent2
5. WPEka Wplegalpages Wordpress2

Recent Vulnerabilities

See more →
CVE-2025-62984
CVSS 6.5medium

WordPress WP AdCenter plugin <= 2.6.1 - Cross Site Scripting (XSS) vulnerability

10/27/2025🔧 No Patch
CVE-2025-53278
CVSS 6.5medium

WordPress WP AdCenter plugin <= 2.6.0 - Cross Site Scripting (XSS) Vulnerability

6/27/2025🔧 No Patch
CVE-2025-31860
CVSS 6.5EPSS 0%medium

WordPress WP AdCenter plugin <= 2.5.8 - Cross Site Scripting (XSS) vulnerability

4/1/2025🔧 No Patch
CVE-2024-11724
CVSS 4.3medium

Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) <= 3.6.5 - Missing Authorization to Authenticated (Subscriber+) Whitelist Script

12/12/2024
CVE-2024-10113
CVSS 6.4medium

WP AdCenter – Ad Manager & Adsense Ads <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpadcenter_ad Shortcode

11/15/2024🔧 No Patch
CVE-2024-8317
CVSS 6.4EPSS 0%medium

WP AdCenter – Ad Manager & Adsense Ads <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ad_alignment Attribute

9/6/2024
CVE-2024-4869
CVSS 7.2EPSS 0%high

WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.2.0 - Unauthenticated Stored Cross-Site Scripting via Client-IP header

6/25/2024🔧 No Patch
CVE-2024-3599
CVSS 5.3EPSS 0%medium

WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.0.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

5/2/2024
CVE-2023-23678
CVSS 7.2high

WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 2.2.5 - CSV Injection vulnerability

11/7/2023
CVE-2023-4968
CVSS 5.5medium

WPLegalPages <= 2.9.2 - Authenticated (Author+) Stored Cross-Site Scripting via Shortcode

10/20/2023

Monitor wpeka in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.