Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WPVibes — Vulnerabilities & Security Advisories 37

Browse all 37 CVE security advisories affecting WPVibes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WPVibes operates as a white-label solution provider, enabling businesses to launch customized WordPress-based platforms for content, e-commerce, and social networking. Despite its utility, the platform has accumulated thirty-four recorded Common Vulnerabilities and Exposures, reflecting significant historical security deficiencies. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from inadequate input validation and insufficient access controls within its modular architecture. The high volume of CVEs suggests systemic issues in code review processes and dependency management, allowing attackers to compromise server integrity or steal user data. While specific major public breaches are not widely documented in mainstream media, the persistent nature of these vulnerabilities indicates a critical need for rigorous patching and security auditing. Organizations utilizing WPVibes must prioritize immediate updates and implement strict security monitoring to mitigate the risk of exploitation inherent in its current software state.

CVE ID Title CVSS Severity Published
CVE-2023-47530 WordPress Redirect 404 Error Page to Homepage or Custom Page with Logs Plugin <= 1.8.7 is vulnerable to SQL Injection — Redirect 404 Error Page to Homepage or Custom Page with Logs CWE-89 7.6 High 2023-12-18
CVE-2023-5381 Elementor Addon Elements <= 1.12.7 - Authenticated (Administrator+) Stored Cross-Site Scripting — Addon Elements for Elementor (formerly Elementor Addon Elements) CWE-79 4.4 Medium 2023-11-15
CVE-2023-4690 Elementor Addon Elements <= 1.12.7 - Cross-Site Request Forgery — Addon Elements for Elementor (formerly Elementor Addon Elements) CWE-352 5.4 Medium 2023-11-15
CVE-2023-4723 Elementor Addon Elements <= 1.12.7 - Missing Authorization to Sensitive Information Exposure — Addon Elements for Elementor (formerly Elementor Addon Elements) CWE-862 5.3 Medium 2023-11-15
CVE-2023-4689 Elementor Addon Elements <= 1.12.7 - Cross-Site Request Forgery — Addon Elements for Elementor (formerly Elementor Addon Elements) CWE-352 5.4 Medium 2023-11-15
CVE-2023-3088 WP Mail Log <= 1.1.1 - Unauthenticated Stored Cross-Site Scripting via Email — WP Mail Log CWE-79 7.2 High 2023-07-12
CVE-2022-45807 WordPress WP Mail Log Plugin <= 1.0.1 is vulnerable to Cross Site Request Forgery (CSRF) — WP Mail Log CWE-352 5.4 Medium 2023-02-02

This page lists every published CVE security advisory associated with WPVibes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.