CVE Tools

Wpmudev

10 CVEs tracked since 2024. Since Oct 2024, none of them reached CISA KEV.

Wpmudev CVEs per month

Oct 2024 to Nov 2024. Point at a month, or focus the strip and use the arrow keys.
Wpmudev CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-1050
2024-1150

Products

The products that kept showing up in Wpmudev's monthly top three, with their CVEs summed over those months.

  1. Forminator Forms41 month
  2. Forminator Forms – Contact Form, Payment Form & Custom Form Builder41 month
  3. Hustle – Email Marketing, Lead Generation, Optins, Popups21 month
  4. Branda – White Label & Branding, Free Login Page Customizer11 month
  5. Broken Link Checker11 month
  6. Defender Security11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Wpmudev.

  1. CVE-2026-92229Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter9.1
  2. CVE-2026-83627Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log9.8
  3. CVE-2026-75528Broken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log7.2
  4. CVE-2026-76581WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion9.8
  5. CVE-2026-18324Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field7.2
  6. CVE-2026-18328Forminator Forms <= 1.57.0 - Unauthenticated DOM-Based Cross-Site Scripting via 'error_description' Parameter7.2
  7. CVE-2026-18323Forminator Forms <= 1.57.0.2 - Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft)7.2
  8. CVE-2026-15748Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration9.8
  9. CVE-2026-12998Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter5.3
  10. CVE-2026-15459WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint8.1
  11. CVE-2026-18325Forminator Forms <= 1.56.1 - Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field7.2
  12. CVE-2026-11551Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover9.8
  13. CVE-2026-6214Forminator Forms <= 1.53.0 - Missing Authorization to Authenticated (Subscriber+) Scheduled Form Submission Export via forminator_export_entries Action on wp_loaded Hook6.5
  14. CVE-2026-6222Forminator Forms <= 1.51.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'forminator_action' Parameter5.3
  15. CVE-2026-5192Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.52.1 - Unauthenticated Arbitrary File Read via 'upload-1[file][file_path]'7.5

The record

Peak rank
#164 in Oct 2024
Busiest month shown
Oct 2024, 5 CVEs
Months with a KEV entry
0 since Oct 2024
Monthly snapshots
2 since 2024
Wpmudev's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store