CVEs we hold for Wpmet
Records whose assigning authority named Wpmet as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-54197WordPress GetGenie plugin <= 4.4.1 - Sensitive Data Exposure vulnerabilityWpmet GetGenie
CVE-2026-49053WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulnerabilityWpmet ElementsKit Elementor addons Lite
CVE-2026-49052WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulnerabilityWpmet ElementsKit Elementor addons Lite
CVE-2026-4246ElementsKit Pro <= 4.10.1 - Unauthenticated Stored Cross-Site Scripting via 's' Parameterwpmet ElementsKit Pro
CVE-2026-24611WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerabilityWPMet MetForm Pro
CVE-2026-24610WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerabilityWPMet MetForm Pro
CVE-2026-1782MetForm Pro <= 3.9.7 - Unauthenticated Payment Amount Manipulation via 'mf-calculation'Wpmet MetForm Pro
CVE-2025-0321ElementsKit Pro <= 3.7.8 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via url Parameterwpmet ElementsKit Pro
CVE-2024-7064ElementsKit Pro <= 3.6.5 - Authenticated (Contributor+) Stored Cross-Site Scriptingwpmet ElementsKit Pro
CVE-2024-7063ElementsKit Pro <= 3.6.6 - Authenticated (Contributor+) Sensitive Information Exposurewpmet ElementsKit Pro
CVE-2024-5263ElementsKit Elementor addons and Templates Library <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting…wpmet ElementsKit Pro
CVE-2024-4452ElementsKit Pro <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scriptingwpmet ElementsKit Pro
CVE-2024-4404ElementsKit PRO <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgerywpmet ElementsKit Pro
CVE-2024-3598ElementsKit Pro <= 3.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ekit_btn_id'wpmet ElementsKit Pro
CVE-2024-3500ElementsKit Pro <= 3.6.0 - Authenticated (Contributor+) Local File Inclusion via Price Menu, Hotspot, and Advanced…wpmet ElementsKit Pro
CVE-2024-34758WordPress FundEngine – Donation and Crowdfunding Platform plugin <= 1.6.4 - Broken Access Control vulnerabilityWpmet WP Fundraising Donation and Crowdfunding Platform
CVE-2024-32685WordPress WP Ultimate Review plugin <= 2.2.5 - Review Score Manipulation vulnerabilityWpmet Wp Ultimate Review
CVE-2024-32684WordPress WP Ultimate Review plugin <= 2.2.5 - Broken Access Control on Review vulnerabilityWpmet Wp Ultimate Review
CVE-2024-32683WordPress WP Ultimate Review plugin <= 2.2.5 - Insecure Direct Object References (IDOR) vulnerabilityWpmet Wp Ultimate Review
CVE-2023-46085WordPress Wp Ultimate Review Plugin <= 2.2.4 is vulnerable to Cross Site Request Forgery (CSRF)Wpmet Wp Ultimate Review
CVE-2023-39993WordPress ElementsKit Lite plugin <= 2.9.0 - Broken Access Control vulnerabilityWpmet Elements kit Elementor addons
CVE-2023-28987WordPress Wp Ultimate Review Plugin <= 2.0.3 is vulnerable to Cross Site Request Forgery (CSRF)Wpmet Wp Ultimate Review
CVE-2023-28751WordPress Wp Ultimate Review Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)Wpmet Wp Ultimate Review
CVE-2022-47160WordPress Wp Social Plugin <= 1.9.0 is vulnerable to Sensitive Data ExposureWpmet Wp Social Login and Register Social Counter
CVE-2022-45371WordPress ShopEngine Plugin <= 4.1.1 is vulnerable to Cross Site Request Forgery (CSRF)Wpmet ShopEngine
CVE-2021-24258ElementsKit and ElementsKit Pro < 2.2.0 - Contributor+ Stored XSSWpmet Elements Kit Pro
27 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.