SecAlerts
wpmu dev logo

wpmu dev

Security Risk Profile

42
/100
medium

Security Risk Score

Comprehensive risk assessment based on 31 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 15, 2024 to present

31
Total CVEs
11
Critical+High
0
Exploited
5
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
5
Critical/High
Risk Level
42/100
medium
🆕 1Fresh (<7d)📈 2 in Last 30 Days

Severity Distribution

Critical
4
High
7
Medium
19
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
10

Age Distribution

Common Weaknesses (CWE)

1
XSS
6
2
Path Traversal
2
3
SQL Injection
1
4
CSRF
1

Most Affected Products

1. WPMU DEV Forminator9
2. wpmudev Forminator Forms Wordpress5
3. WPMU DEV Forminator Forms4
4. Incsub Forminator Wordpress4
5. wpmudev Defender Wordpress4

Recent Vulnerabilities

See more →
CVE-2026-15459
CVSS 8.1high

WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint

8/6/2026🔧 No Patch
CVE-2026-57815
CVSS 7.5high

WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability

7/13/2026🔧 No Patch
CVE-2026-25431
CVSS 5.3medium

WordPress Hustle plugin <= 7.8.10.1 - Broken Access Control vulnerability

5/12/2026
CVE-2026-6222
CVSS 5.3medium

Forminator Forms <= 1.51.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'forminator_action' Parameter

5/7/2026🔧 No Patch
CVE-2026-2729
CVSS 5.3medium

Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.52.0 - Missing Authorization to Unauthenticated Stripe PaymentIntent Reuse / Underpayment Bypass via 'paymentid' Parameter

5/5/2026🔧 No Patch
CVE-2026-39466
CVSS 7.6high

WordPress Broken Link Checker plugin <= 2.4.7 - SQL Injection vulnerability

4/8/2026🔧 No Patch
CVE-2026-2263
CVSS 5.3medium

Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.10.2 - Missing Authorization to Unauthenticated Conversion Tracking Data Manipulation

4/7/2026🔧 No Patch
CVE-2026-32409
CVSS 5.3EPSS 0%medium

WordPress Forminator plugin <= 1.50.2 - Broken Access Control vulnerability

3/13/2026🔧 No Patch
CVE-2026-24998
CVSS 5.3EPSS 0%medium

WordPress Hustle plugin <= 7.8.9.2 - Sensitive Data Exposure vulnerability

2/3/2026🔧 No Patch
CVE-2025-22288
CVSS 4.1medium

WordPress Smush Image Compression and Optimization plugin <= 3.17.0 - Directory Traversal vulnerability

11/6/2025🔧 No Patch

Monitor wpmu dev in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.