CVE Tools

Wpexperts

11 CVEs tracked since 2023. Since Jul 2023, none of them reached CISA KEV.

Wpexperts CVEs per month

Jul 2023 to Jan 2024. Point at a month, or focus the strip and use the arrow keys.
Wpexperts CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0750
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-0160

Products

The products that kept showing up in Wpexperts's monthly top three, with their CVEs summed over those months.

  1. Post Smtp92 months
  2. Mycred11 month
  3. Wp Pdf Generator11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Wpexperts.

  1. CVE-2026-81278WordPress Post SMTP plugin 4.0.0-beta.1 - Settings Change vulnerability5.4
  2. CVE-2026-32466WordPress Gravity Forms Bookings premium plugin <= 2.1 - SQL Injection vulnerability8.5
  3. CVE-2026-48838WordPress Post SMTP plugin <= 3.6.2 - Cross Site Scripting (XSS) vulnerability7.1
  4. CVE-2024-13844Post SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns Parameter4.9
  5. CVE-2024-13713WPExperts Square For GiveWP <= 1.3.1 - Authenticated (Subscriber+) SQL Injection6.5
  6. CVE-2025-0521Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting7.2
  7. CVE-2025-24680WordPress WP Multi Store Locator Plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability7.1
  8. CVE-2025-22800WordPress Post SMTP plugin <= 2.9.11 - Broken Access Control vulnerability4.3
  9. CVE-2024-12475WP Multi Store Locator <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
  10. CVE-2024-52436WordPress Post SMTP plugin <= 2.9.9 - SQL Injection vulnerability7.6
  11. CVE-2024-43214WordPress myCred plugin <= 2.7.2 - Sensitive Data Exposure vulnerability5.3
  12. CVE-2024-4753WP Secure Maintenance < 1.7 - Admin+ Stored XSS4.8
  13. CVE-2024-1639License Manager for WooCommerce <= 3.0.6 - Improper Authorization to Authenticated(Contributor+) Sensitive Information Exposure6.5
  14. CVE-2023-52233WordPress POST SMTP Mailer plugin <= 2.8.6 - Broken Access Control on API vulnerability8.6
  15. CVE-2024-5207POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection7.2

The record

Peak rank
#133 in Jan 2024
Busiest month shown
Jan 2024, 6 CVEs
Months with a KEV entry
0 since Jul 2023
Monthly snapshots
2 since 2023
Wpexperts's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store