Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WPFactory — Vulnerabilities & Security Advisories 48

Browse all 48 CVE security advisories affecting WPFactory. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WPFactory operates as a software development firm specializing in WordPress plugins and themes, catering to web developers and site administrators seeking extended functionality. Historically, its products have been associated with forty-seven recorded Common Vulnerabilities and Exposures (CVEs), predominantly involving remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from insufficient input validation and improper capability checks within plugin code, allowing unauthenticated attackers to compromise affected sites. While specific major incidents are rarely publicized as distinct breaches, the high volume of CVEs indicates systemic security oversight in the development lifecycle. The company’s portfolio includes popular tools for SEO, security, and page building, yet the recurring nature of these exploits highlights persistent challenges in maintaining secure coding standards for widely deployed WordPress extensions.

CVE ID Title CVSS Severity Published
CVE-2025-31553 WordPress Advanced WooCommerce Product Sales Reporting plugin <= 4.1.1 - SQL Injection vulnerability — Advanced WooCommerce Product Sales Reporting CWE-89 9.3 Critical 2025-04-01
CVE-2025-31848 WordPress WordPress Adverts Plugin plugin <= 1.4 - Broken Access Control vulnerability — Adverts CWE-862 5.3 Medium 2025-04-01
CVE-2025-31598 WordPress Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin <= 4.0.3 - Stored Cross Site Scripting (XSS) vulnerability — Quantity Dynamic Pricing & Bulk Discounts for WooCommerce CWE-79 6.5 Medium 2025-03-31
CVE-2025-22673 WordPress EAN Barcode Generator <= 5.3.5 - Broken Access Control vulnerability — EAN for WooCommerce CWE-862 4.3 Medium 2025-03-27
CVE-2025-30781 WordPress Scheduled & Automatic Order Status Controller for WooCommerce plugin <= 3.7.1 - Open Redirection Vulnerability — Scheduled & Automatic Order Status Controller for WooCommerce CWE-601 4.7 Medium 2025-03-27
CVE-2024-56228 WordPress Wishlist for WooCommerce: Multi Wishlists Per Customer plugin <= 3.1.2 - Reflected Cross Site Scripting (XSS) vulnerability — Wishlist for WooCommerce CWE-79 7.1 High 2024-12-31
CVE-2024-54332 WordPress WP Currency Exchange Rates plugin <= 1.2.0 - CSRF to Stored XSS vulnerability — WP Currency Exchange Rates CWE-352 7.1 High 2024-12-16
CVE-2023-23868 WordPress Cost of Goods for WooCommerce plugin <= 2.8.6 - Broken Access Control vulnerability — Cost of Goods for WooCommerce CWE-862 5.4 Medium 2024-12-09
CVE-2024-54209 WordPress Awesome Shortcodes plugin <= 1.7.2 - Reflected Cross Site Scripting (XSS) vulnerability — Awesome Shortcodes CWE-79 7.1 High 2024-12-06
CVE-2024-44061 WordPress EU/UK VAT Manager for WooCommerce plugin <= 2.12.14 - CSRF to Cross Site Scripting (XSS) vulnerability — EU/UK VAT Manager for WooCommerce CWE-79 7.1 High 2024-10-20
CVE-2024-49305 WordPress Customer Email Verification for WooCommerce plugin <= 2.8.10 - SQL Injection vulnerability — Email Verification for WooCommerce CWE-89 9.3 Critical 2024-10-17
CVE-2024-43127 WordPress Products, Order & Customers Export for WooCommerce plugin <= 2.0.11 - Reflected Cross Site Scripting (XSS) vulnerability — Products, Order & Customers Export for WooCommerce CWE-79 7.1 High 2024-08-12
CVE-2024-31276 WordPress Products, Order & Customers Export for WooCommerce plugin <= 2.0.8 - Broken Access Control vulnerability — Products, Order & Customers Export for WooCommerce CWE-862 5.3 Medium 2024-06-09
CVE-2024-34370 WordPress EAN for WooCommerce plugin <= 4.8.9 - Arbitrary Option Update to Privilege Escalation vulnerability — EAN for WooCommerce CWE-269 7.2 High 2024-05-17
CVE-2024-30536 WordPress Slugs Manager plugin <= 2.6.7 - Cross Site Request Forgery (CSRF) vulnerability — Slugs Manager CWE-352 4.3 Medium 2024-03-31
CVE-2023-51399 WordPress Back Button Widget Plugin <= 1.6.3 is vulnerable to Cross Site Scripting (XSS) — Back Button Widget CWE-79 6.5 Medium 2023-12-29
CVE-2023-47547 WordPress Products, Order & Customers Export for WooCommerce Plugin <= 2.0.7 is vulnerable to Cross Site Scripting (XSS) — Products, Order & Customers Export for WooCommerce CWE-79 7.1 High 2023-11-14
CVE-2023-36689 WordPress WPFactory Helper Plugin <= 1.5.2 is vulnerable to Cross Site Scripting (XSS) — WPFactory Helper CWE-79 7.1 High 2023-08-05

This page lists every published CVE security advisory associated with WPFactory. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.