Browse all 5 CVE security advisories affecting XWP. AI-powered Chinese analysis, POCs, and references for each vulnerability.
XWP develops WordPress-focused security solutions and services, protecting websites from common web vulnerabilities. Historically, their products have faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation issues. The company maintains a moderate security posture with four CVEs recorded, primarily related to input validation and access control flaws. While no major security incidents have been widely documented, their codebase occasionally contains insufficient sanitization of user inputs and improper privilege checks. XWP's security characteristics reflect typical WordPress plugin challenges, emphasizing the need for regular updates and proper input handling to mitigate potential exploitation risks in their security offerings.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-11907 | Stream <= 4.2.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API — Stream – Activity Log & Audit Trail CWE-862 | 6.5 | Medium | 2026-08-07 |
This page lists every published CVE security advisory associated with XWP. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.