Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

wpdevteam — Vulnerabilities & Security Advisories 92

Browse all 92 CVE security advisories affecting wpdevteam. AI-powered Chinese analysis, POCs, and references for each vulnerability.

wpdevteam operates as a software development entity primarily focused on creating plugins and themes for the WordPress ecosystem. Their portfolio includes various tools designed to extend website functionality, making them a frequent target for automated vulnerability scanners. Historically, their codebase has exhibited a high frequency of critical security flaws, with 91 CVEs currently on record. These vulnerabilities predominantly involve remote code execution, cross-site scripting, and privilege escalation issues, often stemming from insufficient input validation and improper access controls. The sheer volume of disclosed defects suggests systemic weaknesses in their development and testing processes rather than isolated incidents. While no single catastrophic breach has been publicly detailed as a direct result of these specific CVEs, the persistent nature of these flaws indicates a significant risk to users relying on their software. This pattern highlights the broader challenges associated with maintaining security in widely deployed open-source components.

Found 18 results / 92Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-4658 Gutenberg Essential Blocks <= 6.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-79 6.4 Medium2026-05-02
CVE-2025-11369 Essential Blocks <= 5.7.2 - Missing Authorization To Authenticated (Author+) Information Disclosure — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-862 4.3 Medium2025-12-17
CVE-2025-11270 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 5.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-79 6.4 Medium2025-10-18
CVE-2025-11361 Essential Blocks <= 5.7.1 - Authenticated (Author+) Server-Side Request Forgery — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-918 6.4 Medium2025-10-18
CVE-2025-4682 Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-79 6.4 Medium2025-05-27
CVE-2025-1664 Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-79 6.4 Medium2025-03-08
CVE-2024-13803 Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-79 6.4 Medium2025-02-26
CVE-2024-12045 Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 5.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-79 4.4 Medium2025-01-08
CVE-2024-4891 Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.12 - Authenticated (Contributor+) Stored Cross-Site Scripting — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-79 6.4 Medium2024-05-18
CVE-2024-3818 Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.9 - Authenticated (Contributor+) DOM-Based Cross-Site Scripting via "Social Icons" Block — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-79 5.4 Medium2024-04-19
CVE-2024-2255 Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-79 6.4 Medium2024-03-20
CVE-2024-1854 Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-20 6.4 Medium2024-03-13
CVE-2023-7071 Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-79 6.4 Medium2024-01-11
CVE-2023-2083 Essential Blocks <= 4.0.6 - Missing Authorization via save — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-862 4.3 Medium2023-06-09
CVE-2023-2087 Essential Blocks <= 4.0.6 - Cross-Site Request Forgery via save — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-352 4.3 Medium2023-06-09
CVE-2023-2085 Essential Blocks <= 4.0.6 - Missing Authorization via templates — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-862 4.3 Medium2023-06-09
CVE-2023-2086 Essential Blocks <= 4.0.6 - Missing Authorization via template_count — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-862 4.3 Medium2023-06-09
CVE-2023-2084 Essential Blocks <= 4.0.6 - Missing Authorization via get — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-862 4.3 Medium2023-06-09

This page lists every published CVE security advisory associated with wpdevteam. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.