Browse all 8 CVE security advisories affecting wisdmlabs. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Wisdmlabs develops WordPress and WooCommerce solutions, with 8 CVEs recorded primarily involving RCE and XSS vulnerabilities in their plugins. Historically, their code has shown weaknesses in input validation and insufficient access controls, leading to privilege escalation risks. While no major public security incidents have been documented, their vulnerabilities typically stem from inadequate sanitization of user inputs and improper implementation of security checks. The company's products have required patches for issues allowing attackers to execute unauthorized code or manipulate content through cross-site scripting, highlighting ongoing challenges in secure development practices for their WordPress ecosystem integrations.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-24570 | WordPress Edwiser Bridge plugin <= 4.3.2 - Broken Access Control vulnerability — Edwiser BridgeCWE-862 | 5.4 | Medium | 2026-01-23 |
| CVE-2025-24593 | WordPress Edwiser Bridge plugin <= 3.0.8 - Reflected Cross Site Scripting (XSS) vulnerability — Edwiser BridgeCWE-79 | 7.1 | High | 2025-01-27 |
| CVE-2024-49311 | WordPress Edwiser Bridge plugin <= 3.0.7 - Cross Site Scripting (XSS) vulnerability — Edwiser BridgeCWE-79 | 6.5 | Medium | 2024-10-17 |
| CVE-2024-49312 | WordPress Edwiser Bridge plugin <= 3.0.7 - Server Side Request Forgery (SSRF) vulnerability — Edwiser BridgeCWE-918 | 4.9 | Medium | 2024-10-17 |
| CVE-2024-31260 | WordPress Edwiser Bridge plugin <= 3.0.2 - SQL Injection vulnerability — Edwiser BridgeCWE-89 | 7.6 | High | 2024-04-07 |
This page lists every published CVE security advisory associated with wisdmlabs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.