CVE Tools

Wpmet

37 CVEs tracked since 2023. Since Jun 2023, none of them reached CISA KEV.

Wpmet CVEs per month

Jun 2023 to Jun 2024. Point at a month, or focus the strip and use the arrow keys.
Wpmet CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-06120
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-0370
2024-0460
2024-0570
2024-0650

Products

The products that kept showing up in Wpmet's monthly top three, with their CVEs summed over those months.

  1. Metform Elementor Contact Form Builder133 months
  2. Elements Kit Elementor Addons83 months
  3. Elementskit Pro53 months
  4. Elementskit42 months
  5. Wp Ultimate Review32 months
  6. Elementskit Elementor Addons11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Wpmet.

  1. CVE-2026-4246ElementsKit Pro <= 4.10.1 - Unauthenticated Stored Cross-Site Scripting via 's' Parameter6.1
  2. CVE-2026-24611WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability9.1
  3. CVE-2026-24610WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability4.3
  4. CVE-2026-54197WordPress GetGenie plugin <= 4.4.1 - Sensitive Data Exposure vulnerability6.5
  5. CVE-2026-49053WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulnerability5.3
  6. CVE-2026-49052WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulnerability4.3
  7. CVE-2026-1782MetForm Pro <= 3.9.7 - Unauthenticated Payment Amount Manipulation via 'mf-calculation'5.3
  8. CVE-2026-1261MetForm Pro <= 3.9.6 - Unauthenticated Stored Cross-Site Scripting7.2
  9. CVE-2025-3614ElementsKit Elementor Addons and Templates <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget6.4
  10. CVE-2025-4479ElementsKit Lite <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget6.4
  11. CVE-2025-46253WordPress GutenKit plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability6.5
  12. CVE-2024-11180ElementsKit Elementor addons <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
  13. CVE-2025-1506Wp Social Login and Register Social Counter <= 3.1.0 - Cross-Site Request Forgery to Settings Update4.3
  14. CVE-2025-0968ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function5.3
  15. CVE-2025-1005ElementsKit Elementor addons <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget6.4

The record

Peak rank
#54 in Jun 2023
Busiest month shown
Jun 2023, 12 CVEs
Months with a KEV entry
0 since Jun 2023
Monthly snapshots
5 since 2023
Wpmet's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store