Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

The Ultimate WordPress Toolkit – WP Extended — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in The Ultimate WordPress Toolkit – WP Extended, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the vendor WP Extended, specifically focusing on their product known as The Ultimate WordPress Toolkit. It provides a comprehensive view of security weaknesses associated with this specific WordPress extension, allowing users to analyze risk patterns across different releases and configurations. The content collected here encompasses a wide variety of vulnerability types, including but not limited to cross-site scripting, SQL injection, privilege escalation, and arbitrary file inclusion. These entries are drawn from public security advisories, patch notes, and community-reported issues spanning the last five years. By consolidating these disparate sources, the database offers a chronological record of how the product has evolved in response to emerging threats. Users can utilize this resource to track a vendor's advisory history and see how quickly security patches are released after a flaw is disclosed. It also allows researchers to understand specific weakness classes that tend to affect this toolkit, such as how input sanitization issues manifest in its specific shortcode implementations. Additionally, one can look up a product's vulnerability history to assess its long-term maintenance quality and stability. This structured overview helps developers, site administrators, and security analysts make informed decisions about whether to update, replace, or further harden their installation of the toolkit.

Vendor: WP Extended

CVE IDTitleCVSSSeverityPublished
CVE-2026-4314 The Ultimate WordPress Toolkit – WP Extended <= 3.2.4 - Authenticated (Subscriber+) Privilege Escalation via Menu Editor Module CWE-269 8.8 High2026-03-22
CVE-2025-4963 WP Extended <= 3.0.15 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload CWE-79 6.4 Medium2025-05-28
CVE-2025-30796 WordPress The Ultimate WordPress Toolkit – WP Extended plugin <= 3.0.14 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2025-04-01
CVE-2024-13554 The Ultimate WordPress Toolkit – WP Extended <= 3.0.13 - Missing Authorization to Unauthenticated Post Order Manipulation CWE-862 5.3 Medium2025-02-12
CVE-2024-13184 The Ultimate WordPress Toolkit – WP Extended <= 3.0.12 - Unauthenticated SQL Injection via Login Attempts Module CWE-89 7.5 High2025-01-18
CVE-2024-11816 The Ultimate WordPress Toolkit – WP Extended <= 3.0.11 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution CWE-862 8.8 High2025-01-08
CVE-2024-11916 The Ultimate WordPress Toolkit – WP Extended <= 3.0.11 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting CWE-862 7.4 High2025-01-08
CVE-2024-9347 The Ultimate WordPress Toolkit – WP Extended <= 3.0.9 - Reflected Cross-Site Scripting CWE-79 6.1 Medium2024-10-17
CVE-2024-47386 WordPress WP Extended plugin <= 3.0.8 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-10-05
CVE-2024-8123 The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Insecure Direct Object Reference CWE-639 5.4 Medium2024-09-04
CVE-2024-8121 The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Missing Authorization to Admin Username Change CWE-862 5.4 Medium2024-09-04
CVE-2024-8106 The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Authenticated (Subscriber+) Sensitive Information Exposure CWE-200 6.5 Medium2024-09-04
CVE-2024-8102 The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Authenticated (Subscriber+) Arbitrary Options Update CWE-862 8.8 High2024-09-04
CVE-2024-8119 The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Reflected Cross-Site Scripting via page CWE-79 6.1 Medium2024-09-04
CVE-2024-8104 The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Directory Traversal to Authenticated (Subscriber+) Arbitrary File Download CWE-22 8.8 High2024-09-04
CVE-2024-8117 The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Reflected Cross-Site Scripting via selected_option CWE-79 6.1 Medium2024-09-04
CVE-2024-37259 WordPress WP Extended plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-07-22

All 17 known CVE vulnerabilities affecting The Ultimate WordPress Toolkit – WP Extended with full Chinese analysis, references, and POCs where available.