Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Wpmet — Vulnerabilities & Security Advisories 30

Browse all 30 CVE security advisories affecting Wpmet. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Wpmet operates as a developer of WordPress plugins and themes, primarily targeting the construction of real estate, classifieds, and directory websites. Its extensive product portfolio has resulted in twenty-one recorded Common Vulnerabilities and Exposures (CVEs), highlighting significant security gaps within its codebase. Historically, the most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Privilege Escalation, often stemming from insufficient input validation and improper access controls in admin-facing endpoints. These flaws frequently allow unauthenticated attackers to execute arbitrary commands or manipulate user sessions. While no single catastrophic data breach has been publicly attributed solely to Wpmet infrastructure, the high volume of exploitable plugins suggests a systemic lack of rigorous security auditing. Users relying on these tools face elevated risks of site compromise, necessitating immediate updates and strict monitoring to mitigate the impact of known exploits.

CVE ID Title CVSS Severity Published
CVE-2026-103339 WordPress Metform plugin <= 4.3.0 - Cross Site Scripting (XSS) vulnerability — Metform CWE-79 6.5 Medium 2026-10-01
CVE-2026-103063 WordPress ElementsKit Elementor addons Lite plugin <= 4.0.6 - Cross Site Scripting (XSS) vulnerability — ElementsKit Elementor addons Lite CWE-79 6.5 Medium 2026-10-01
CVE-2026-103064 WordPress ElementsKit Elementor addons Lite plugin <= 4.0.6 - Cross Site Scripting (XSS) vulnerability — ElementsKit Elementor addons Lite CWE-79 6.5 Medium 2026-10-01
CVE-2026-4246 ElementsKit Pro <= 4.10.1 - Unauthenticated Stored Cross-Site Scripting via 's' Parameter — ElementsKit Pro CWE-79 6.1 Medium 2026-08-28
CVE-2026-24611 WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability — MetForm Pro CWE-862 9.1 Critical 2026-06-17
CVE-2026-24610 WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability — MetForm Pro CWE-862 4.3 Medium 2026-06-17
CVE-2026-54197 WordPress GetGenie plugin <= 4.4.1 - Sensitive Data Exposure vulnerability — GetGenie CWE-201 6.5 Medium 2026-06-16
CVE-2026-49053 WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulnerability — ElementsKit Elementor addons Lite CWE-862 5.3 Medium 2026-05-27
CVE-2026-49052 WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulnerability — ElementsKit Elementor addons Lite CWE-862 4.3 Medium 2026-05-27
CVE-2026-1782 MetForm Pro <= 3.9.7 - Unauthenticated Payment Amount Manipulation via 'mf-calculation' — MetForm Pro CWE-20 5.3 Medium 2026-04-15
CVE-2026-1261 MetForm Pro <= 3.9.6 - Unauthenticated Stored Cross-Site Scripting — MetForm Pro CWE-79 7.2 High 2026-03-10
CVE-2025-0321 ElementsKit Pro <= 3.7.8 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via url Parameter — ElementsKit Pro CWE-79 6.4 Medium 2025-01-28
CVE-2024-7063 ElementsKit Pro <= 3.6.6 - Authenticated (Contributor+) Sensitive Information Exposure — ElementsKit Pro CWE-200 4.3 Medium 2024-08-15
CVE-2024-7064 ElementsKit Pro <= 3.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting — ElementsKit Pro CWE-79 6.4 Medium 2024-08-15
CVE-2023-39993 WordPress ElementsKit Lite plugin <= 2.9.0 - Broken Access Control vulnerability — Elements kit Elementor addons CWE-862 4.3 Medium 2024-06-19
CVE-2024-5263 ElementsKit Elementor addons and Templates Library <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Motion Text and Table Widgets — ElementsKit Pro CWE-79 6.4 Medium 2024-06-15
CVE-2024-4404 ElementsKit PRO <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery — ElementsKit Pro CWE-918 8.5 High 2024-06-14
CVE-2024-34758 WordPress FundEngine – Donation and Crowdfunding Platform plugin <= 1.6.4 - Broken Access Control vulnerability — WP Fundraising Donation and Crowdfunding Platform CWE-862 5.3 Medium 2024-06-11
CVE-2024-4452 ElementsKit Pro <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting — ElementsKit Pro CWE-79 6.4 Medium 2024-05-21
CVE-2024-32685 WordPress WP Ultimate Review plugin <= 2.2.5 - Review Score Manipulation vulnerability — Wp Ultimate Review CWE-602 5.3 Medium 2024-05-17
CVE-2024-3500 ElementsKit Pro <= 3.6.0 - Authenticated (Contributor+) Local File Inclusion via Price Menu, Hotspot, and Advanced Toggle Widgets — ElementsKit Pro CWE-98 8.8 High 2024-05-02
CVE-2024-32684 WordPress WP Ultimate Review plugin <= 2.2.5 - Broken Access Control on Review vulnerability — Wp Ultimate Review CWE-862 5.3 Medium 2024-04-22
CVE-2024-32683 WordPress WP Ultimate Review plugin <= 2.2.5 - Insecure Direct Object References (IDOR) vulnerability — Wp Ultimate Review CWE-639 5.3 Medium 2024-04-19
CVE-2024-3598 ElementsKit Pro <= 3.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ekit_btn_id' — ElementsKit Pro CWE-79 6.4 Medium 2024-04-19
CVE-2022-47160 WordPress Wp Social Plugin <= 1.9.0 is vulnerable to Sensitive Data Exposure — Wp Social Login and Register Social Counter CWE-200 6.5 Medium 2024-01-19
CVE-2023-28987 WordPress Wp Ultimate Review Plugin <= 2.0.3 is vulnerable to Cross Site Request Forgery (CSRF) — Wp Ultimate Review CWE-352 4.3 Medium 2023-11-12
CVE-2023-46085 WordPress Wp Ultimate Review Plugin <= 2.2.4 is vulnerable to Cross Site Request Forgery (CSRF) — Wp Ultimate Review CWE-352 4.3 Medium 2023-10-22
CVE-2023-28751 WordPress Wp Ultimate Review Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS) — Wp Ultimate Review CWE-79 5.9 Medium 2023-06-23
CVE-2022-45371 WordPress ShopEngine Plugin <= 4.1.1 is vulnerable to Cross Site Request Forgery (CSRF) — ShopEngine CWE-352 5.4 Medium 2023-05-25
CVE-2021-24258 ElementsKit and ElementsKit Pro < 2.2.0 - Contributor+ Stored XSS — Elements Kit Lite CWE-79 5.4 - 2021-05-05

This page lists every published CVE security advisory associated with Wpmet. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.