SecAlerts
w

wpmanageninja

Security Risk Profile

36
/100
low

Security Risk Score

Comprehensive risk assessment based on 29 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 30, 2021 to present

29
Total CVEs
11
Critical+High
0
Exploited
5
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
5
Critical/High
Risk Level
36/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
1
High
10
Medium
18
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
XSS
10
2
SQL Injection
3
3
SSRF
2
4
Path Traversal
1
5
Infoleak
1

Most Affected Products

1. WPManageNinja Ninja Tables Wordpress10
2. WPManageNinja Fluent Support Wordpress5
3. WPManageNinja Fluent Forms4
4. WPManageNinja Ninja Tables3
5. WPManageNinja Fluentsmtp Wordpress3

Recent Vulnerabilities

See more →
CVE-2026-86612
CVSS 5.6medium

Ninja Tables < 5.2.17 - Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Data Source

Sep 23, 2026🔧 No Patch
CVE-2026-5395
CVSS 8.2high

Fluent Forms <= 6.2.0 - Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter

May 14, 2026🔧 No Patch
CVE-2026-6828
CVSS 6.4EPSS 0%medium

Fluent Forms <= 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'permission_message' Shortcode Attribute

May 13, 2026🔧 No Patch
CVE-2026-6344
CVSS 4.9EPSS 0%medium

Fluent Forms <= 6.2.1 - Authenticated (Administrator+) Arbitrary File Read via Path Traversal in Email Attachment

May 6, 2026🔧 No Patch
CVE-2026-2306
CVSS 4.3medium

Ninja Tables <= 5.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Table Creation

May 6, 2026🔧 No Patch
CVE-2025-2940
CVSS 7.2high

Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated Server-Side Request Forgery

Jun 27, 2025
CVE-2025-2939
CVSS 5.6medium

Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated PHP Object Injection to Limited Remote Code Execution

Jun 3, 2025🔧 No Patch
CVE-2024-13568
CVSS 7.5high

Fluent Support – Helpdesk & Customer Support Ticket System <= 1.8.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

Mar 1, 2025🔧 No Patch
CVE-2024-12772
CVSS 6.1medium

Ninja Tables < 5.0.17 - Admin+ Stored XSS

Jan 31, 2025🔧 No Patch
CVE-2023-41952
CVSS 5.3medium

WordPress Fluent Forms plugin <= 5.0.8 - Broken Access Control vulnerability

Dec 13, 2024

Monitor wpmanageninja in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.