wp-buy Vulnerabilities
CVE security advisories and vulnerability history for wp-buy.
Overview
wp-buy has 33 published CVE records since 2019, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 5 have a known public exploit. The average CVSS base score across scored CVEs is 7.5.
This page aggregates every publicly disclosed vulnerability (CVE) affecting wp-buy products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.
Security scorecard
A quick read on wp-buy's vulnerability posture, as a share of its 33 published CVEs.
- Average CVSS
- 7.5
- Critical / high
- 70%
- Actively exploited (KEV)
- 0%
- Public exploit available
- 15%
- Patch available
- 100%
across 33 scored CVEs
23 of 33 scored
0 of 33 CVEs
5 of 33 CVEs
33 of 33 CVEs
Severity and exploitation
How the CVSS severity of wp-buy's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of wp-buy's CVEs are currently listed in CISA's KEV catalog.
Public exploits
5
5 of wp-buy's CVEs have a known public exploit available.
Most affected products
The wp-buy products with the most published CVEs. Follow any product to browse its versions and vulnerabilities.
- WP Content Copy Protection & No Right Click6 CVEs
- Visitor Traffic Real Time Statistics5 CVEs
- Login as User or Customer (User Switching)4 CVEs
- WP Maintenance Mode & Site Under Construction2 CVEs
- Limit Login Attempts2 CVEs
- login_as_user_or_customer_\(user_switching\)2 CVEs
- SEO Redirection Plugin – 301 Redirect Manager (WordPress plugin)2 CVEs
- Limit Login Attempts (Spam Protection)1 CVE
Common weakness types
The CWE weakness categories most often found in wp-buy CVEs. Follow any weakness for its full explanation.
- CWE-352Cross-Site Request Forgery (CSRF)9 CVEs
- CWE-285Improper Authorization8 CVEs
- CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3 CVEs
- CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3 CVEs
- CWE-287Improper Authentication1 CVE
- CWE-348Use of Less Trusted Source1 CVE
- CWE-862Missing Authorization1 CVE
CNAs that assign these CVEs
The CVE Numbering Authorities that publish wp-buy CVE records.
Disclosure activity by year
How many wp-buy CVEs were published each year.
Latest wp-buy CVEs
The most recently disclosed vulnerabilities affecting wp-buy.
- High · CVSS 7.1EPSS 0.1%2026-06-15
- High · CVSS 7.2EPSS 0.3%2026-04-04
- Medium · CVSS 4.3EPSS 0.1%2025-06-06
- Medium · CVSS 4.8EPSS 0.3%2025-05-15
- Medium · CVSS 6.1EPSS 0.5%2025-05-15
- Medium · CVSS 4.3EPSS 0.2%2025-04-04
- High · CVSS 7.1EPSS 0.1%2025-03-31
- High · CVSS 7.1EPSS 0.1%2025-03-31
- Medium · CVSS 4.7EPSS 0.8%2025-02-17
- Medium · CVSS 4.3EPSS 0.4%2025-01-02
- Critical · CVSS 9.3EPSS 0.5%2024-12-13
- High · CVSS 7.1EPSS 0.2%2024-11-19
Track new wp-buy CVEs as they are disclosed and get AI-written analysis and remediation guidance.
Monitor wp-buy CVEsOther vendors
Browse vulnerabilities for other tracked vendors.
Frequently asked questions
Common questions about wp-buy vulnerabilities.
- How many CVEs does wp-buy have?
- wp-buy has 33 published CVE records since 2019, including 10 in the last two years.
- How many wp-buy CVEs are in CISA KEV?
- None of wp-buy's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
- Which wp-buy products have the most CVEs?
- The wp-buy products with the most published CVEs are WP Content Copy Protection & No Right Click, Visitor Traffic Real Time Statistics, Login as User or Customer (User Switching), WP Maintenance Mode & Site Under Construction, Limit Login Attempts.
- What are the most common weakness types in wp-buy CVEs?
- wp-buy's CVEs most often map to these CWE weakness types: CWE-352 (Cross-Site Request Forgery (CSRF)), CWE-285 (Improper Authorization), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).
- Are there public exploits for wp-buy vulnerabilities?
- Yes — 5 of wp-buy's CVEs have a known public exploit.
- How many critical wp-buy vulnerabilities are there?
- wp-buy has 3 critical and 20 high-severity CVEs.
- What is the average severity of wp-buy CVEs?
- The average CVSS base score across wp-buy's scored CVEs is 7.5.
References
- The MITRE CVE Program (opens in a new tab)
- Learn: What is a CVE?
- CWE directory: the weakness types these CVEs map to
- CNA directory: the CNAs that assign these CVEs
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Track wp-buy vulnerabilities
Monitor new wp-buy vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.