Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wpmudev — Vulnerabilities & Security Advisories 52

Browse all 52 CVE security advisories affecting wpmudev. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WPMU DEV operates as a provider of WordPress plugins, themes, and hosting services, primarily targeting website administrators and developers seeking integrated digital asset management solutions. Security audits have identified forty-one Common Vulnerabilities and Exposures (CVEs) associated with its ecosystem, reflecting a pattern of recurring issues within its software portfolio. Historically, these vulnerabilities predominantly manifest as remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from insufficient input validation and inadequate access controls in plugin code. While no single catastrophic data breach has been publicly documented as a direct result of these specific CVEs, the high volume of disclosed issues indicates systemic weaknesses in the development lifecycle. The company has responded to these findings through regular patch releases, yet the persistent nature of these defects suggests ongoing challenges in maintaining rigorous security standards across its diverse range of WordPress extensions.

CVE ID Title CVSS Severity Published
CVE-2024-10580 Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unauthorized Form Submission — Hustle – Email Marketing, Lead Generation, Optins, Popups CWE-862 5.3 Medium 2024-11-27
CVE-2024-10579 Hustle – Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unpublished Form Exposure — Hustle – Email Marketing, Lead Generation, Optins, Popups CWE-862 4.3 Medium 2024-11-26
CVE-2024-9371 Branda – White Label & Branding, Custom Login Page Customizer <= 3.4.19 - Reflected Cross-Site Scripting — Branda – White Label & Branding, Free Login Page Customizer CWE-79 6.1 Medium 2024-11-21
CVE-2024-9700 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.36.0 - Insecure Direct Object Reference to Submission Manipulation — Forminator Forms – Contact Form, Payment Form & Custom Form Builder CWE-639 5.3 Medium 2024-10-31
CVE-2024-10402 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation — Forminator Forms – Contact Form, Payment Form & Custom Form Builder CWE-862 7.5 High 2024-10-26
CVE-2024-9351 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Quiz Creation — Forminator Forms – Contact Form, Payment Form & Custom Form Builder CWE-352 4.3 Medium 2024-10-17
CVE-2024-9352 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Custom Form Creation — Forminator Forms – Contact Form, Payment Form & Custom Form Builder CWE-352 4.3 Medium 2024-10-17
CVE-2024-8981 Broken Link Checker <= 2.4.0 - Reflected Cross-Site Scripting — Broken Link Checker CWE-80 7.1 High 2024-10-01
CVE-2024-7389 Forminator <= 1.29.1 - HubSpot Developer API Key Sensitive Information Exposure — Forminator Forms – Contact Form, Payment Form & Custom Form Builder CWE-522 7.5 High 2024-08-02
CVE-2024-6554 Branda – White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path Disclosure — Branda – White Label & Branding, Free Login Page Customizer CWE-200 5.3 Medium 2024-07-11
CVE-2024-6556 SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer <= 3.10.8 - Unauthenticated Full Path Disclosure — SmartCrawl SEO checker, analyzer & optimizer CWE-200 5.3 Medium 2024-07-10
CVE-2024-5191 Branda – White Label WordPress, Custom Login Page Customizer <= 3.4.17 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload — Branda – White Label & Branding, Free Login Page Customizer CWE-79 6.4 Medium 2024-06-21
CVE-2023-3352 Smush – Lazy Load Images, Optimize & Compress Images <= 3.16.4 - Missing Authorization to Resmush List Deletion — Smush – Image Optimization, Compression, Lazy Load, WebP & CDN CWE-862 4.3 Medium 2024-06-21
CVE-2024-3287 SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer <= 3.10.2 - Missing Authorization — SmartCrawl SEO checker, analyzer & optimizer CWE-862 5.3 Medium 2024-05-02
CVE-2024-1794 Forminator <= 1.29.0 - Unauthenticated Stored Cross-Site Scripting via File Upload — Forminator Forms – Contact Form, Payment Form & Custom Form Builder CWE-79 7.2 High 2024-04-09
CVE-2024-3053 Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.29.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via forminator_form Shortcode — Forminator Forms – Contact Form, Payment Form & Custom Form Builder CWE-79 6.4 Medium 2024-04-09
CVE-2024-0368 Hustle <= 7.8.3 - Sensitive Information Exposure via Exposed Hubspot API Keys — Hustle – Email Marketing, Lead Generation, Optins, Popups CWE-522 8.6 High 2024-03-13
CVE-2023-6133 Forminator <= 1.27.0 - Authenticated (Administrator+) Arbitrary File Upload — Forminator Forms – Contact Form, Payment Form & Custom Form Builder CWE-434 6.6 Medium 2023-11-15
CVE-2023-4596 Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload — Forminator Forms – Contact Form, Payment Form & Custom Form Builder CWE-434 9.8 Critical 2023-08-30
CVE-2021-4425 Defender Security <= 2.4.6 - Cross-Site Request Forgery Bypass — Defender Security – Malware Scanner, Login Security & Firewall CWE-352 4.3 Medium 2023-07-12
CVE-2021-4417 Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.13.4 - Cross-Site Request Forgery Bypass — Forminator Forms – Contact Form, Payment Form & Custom Form Builder CWE-352 5.4 Medium 2023-07-12
CVE-2022-2438 Broken Link Checker <= 1.11.16 - Authenticated (Admin+) PHAR Deserialization — Broken Link Checker CWE-502 7.2 High 2022-09-06

This page lists every published CVE security advisory associated with wpmudev. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.