CVEs we hold for Webfactory
Records whose assigning authority named Webfactory as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-5415WP Captcha PRO <= 5.38 - Authenticated (Subscriber+) Authentication Bypass via Temporary Login Linkwebfactory Advanced Google reCAPTCHA
CVE-2026-5411WP Captcha PRO <= 5.38 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Uploadwebfactory Advanced Google reCAPTCHA
CVE-2026-11426UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail ParameterWebFactory Under Construction Page (Pro)
CVE-2025-3766Login Lockdown & Protection <= 2.11 - Missing Authorization to Authenticated (Subscriber+) Arbitrary IP Whitelistingwebfactory Login Lockdown & Protection
CVE-2025-23968WordPress AiBud WP plugin <= 1.9 - Arbitrary File Upload vulnerabilityWebFactory AiBud WP
CVE-2025-2074Advanced Google reCAPTCHA <= 1.29 - Authenticated (Subscriber+) Limited SQL Injection via 'sSearch' Parameterwebfactory Advanced Google reCAPTCHA
CVE-2025-1262Advanced Google reCaptcha <= 1.27 - Built-in Math CAPTCHA Bypasswebfactory Advanced Google reCAPTCHA
CVE-2025-11707Login Lockdown & Protection <= 2.14 - IP Block Bypasswebfactory Login Lockdown & Protection
CVE-2025-10645WP Reset <= 2.05 - Unauthenticated Sensitive Information Exposure via wf-licensing.logwebfactory WP Reset
CVE-2024-5770WP Force SSL & HTTPS SSL Redirect <= 1.66 - Missing Authorization to Settings Updatewebfactory WP Force SSL & HTTPS SSL Redirect
CVE-2024-5087Minimal Coming Soon – Coming Soon Page <= 2.38 - Missing Authorization to Limited Settings Changewebfactory Minimal Coming Soon – Coming Soon Page
CVE-2024-4661WP Reset <= 2.02 - Missing Authorization to License Key Modificationwebfactory WP Reset
CVE-2024-43259WordPress Order Export for WooCommerce plugin <= 3.23 - Sensitive Data Exposure vulnerabilityWebFactory Order Export for WooCommerce
CVE-2024-1501Database Reset <= 3.22 - Cross-Site Request Forgery to WP Reset Plugin Installationwebfactory Database Reset
CVE-2024-13623Order Export for WooCommerce <= 3.24 - Unauthenticated Sensitive Information Exposure Through Unprotected Directorywebfactory Order Export for WooCommerce
CVE-2024-1340Login Lockdown – Protect Login Form <= 2.08 - Missing Authorizationwebfactory Login Lockdown & Protection
CVE-2024-12034Advanced Google reCAPTCHA <= 1.25 - Brute Force Protection IP Unblockwebfactory Advanced Google reCAPTCHA
CVE-2024-1075Minimal Coming Soon – Coming Soon Page <= 2.37 - Unauthenticated Maintenance Mode Bypasswebfactory Minimal Coming Soon – Coming Soon Page
CVE-2023-6799WP Reset <= 2.0 - Sensitive Information Exposure due to Insufficient Randomnesswebfactory WP Reset
CVE-2023-50837WordPress Login Lockdown Plugin <= 2.06 is vulnerable to SQL InjectionWebFactory Ltd Login Lockdown – Protect Login Form
CVE-2023-5062WordPress Charts <= 0.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodewebfactory WordPress Charts
CVE-2023-49747WordPress Guest Author Plugin <= 2.3 is vulnerable to Cross Site Scripting (XSS)WebFactory Ltd Guest Author
CVE-2023-48745WordPress Captcha Code plugin <= 2.9 - Captcha Bypass vulnerabilityWebFactory Ltd Captcha Code
CVE-2023-1913Maps Widget for Google Maps <= 4.24 - Authenticated (Administrator+) Stored Cross-Site Scriptingwebfactory Maps Widget for Google Maps
CVE-2023-0832Under Construction <= 3.96 - Cross-Site Request Forgery via admin_action_install_weglotwebfactory Under Construction
CVE-2023-0831Under Construction <= 3.96 - Cross-Site Request Forgery via admin_action_ucp_dismiss_noticewebfactory Under Construction
CVE-2021-36909WordPress WP Reset PRO Premium plugin <= 5.98 - Authenticated Database Reset vulnerabilityWebFactory Ltd. WP Reset PRO
CVE-2021-36908WordPress WP Reset PRO Premium Plugin <= 5.98 - Cross-Site Request Forgery (CSRF) vulnerabilityWebFactory Ltd. WP Reset PRO
29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.