Wpmet
37 CVEs tracked since 2023. Since Jun 2023, none of them reached CISA KEV.
Wpmet CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2023-06 | 12 | 0 |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | 7 | 0 |
| 2024-04 | 6 | 0 |
| 2024-05 | 7 | 0 |
| 2024-06 | 5 | 0 |
Products
The products that kept showing up in Wpmet's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Wpmet.
- CVE-2026-4246ElementsKit Pro <= 4.10.1 - Unauthenticated Stored Cross-Site Scripting via 's' Parameter6.1
- CVE-2026-24611WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability9.1
- CVE-2026-24610WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability4.3
- CVE-2026-54197WordPress GetGenie plugin <= 4.4.1 - Sensitive Data Exposure vulnerability6.5
- CVE-2026-49053WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulnerability5.3
- CVE-2026-49052WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulnerability4.3
- CVE-2026-1782MetForm Pro <= 3.9.7 - Unauthenticated Payment Amount Manipulation via 'mf-calculation'5.3
- CVE-2026-1261MetForm Pro <= 3.9.6 - Unauthenticated Stored Cross-Site Scripting7.2
- CVE-2025-3614ElementsKit Elementor Addons and Templates <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget6.4
- CVE-2025-4479ElementsKit Lite <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget6.4
- CVE-2025-46253WordPress GutenKit plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2024-11180ElementsKit Elementor addons <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
- CVE-2025-1506Wp Social Login and Register Social Counter <= 3.1.0 - Cross-Site Request Forgery to Settings Update4.3
- CVE-2025-0968ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function5.3
- CVE-2025-1005ElementsKit Elementor addons <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget6.4
The record
- Peak rank
- #54 in Jun 2023
- Busiest month shown
- Jun 2023, 12 CVEs
- Months with a KEV entry
- 0 since Jun 2023
- Monthly snapshots
- 5 since 2023