Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wcmp — Vulnerabilities & Security Advisories 9

Browse all 9 CVE security advisories affecting wcmp. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WCMP is a WordPress plugin for creating custom post types and managing content, widely used for enhancing website functionality. Historically, it has been susceptible to multiple security vulnerabilities including remote code execution, cross-site scripting, and privilege escalation flaws, with eight CVEs documented. The plugin's complex architecture and extensive permissions have made it a target for attackers. Notable security characteristics include insufficient input validation and inadequate access controls, which have led to several high-severity incidents. In 2021, a critical vulnerability allowed unauthenticated attackers to execute arbitrary code, affecting thousands of websites. Despite patches, ongoing security concerns persist due to the plugin's broad deployment and frequent updates.

Found 1 results / 9Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-12941 MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order_by' Parameter — MultiVendorX – WooCommerce Multivendor Marketplace AI Powered SolutionsCWE-89 6.5 Medium2026-07-16

This page lists every published CVE security advisory associated with wcmp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.