wpvibes Vulnerabilities
CVE security advisories and vulnerability history for wpvibes.
Overview
wpvibes has 46 published CVE records since 2021, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 9 have a known public exploit. The average CVSS base score across scored CVEs is 6.6.
This page aggregates every publicly disclosed vulnerability (CVE) affecting wpvibes products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.
Security scorecard
A quick read on wpvibes's vulnerability posture, as a share of its 46 published CVEs.
- Average CVSS
- 6.6
- Critical / high
- 33%
- Actively exploited (KEV)
- 0%
- Public exploit available
- 20%
- Patch available
- 100%
across 46 scored CVEs
15 of 46 scored
0 of 46 CVEs
9 of 46 CVEs
46 of 46 CVEs
Severity and exploitation
How the CVSS severity of wpvibes's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of wpvibes's CVEs are currently listed in CISA's KEV catalog.
Public exploits
9
9 of wpvibes's CVEs have a known public exploit available.
Most affected products
The wpvibes products with the most published CVEs. Follow any product to browse its versions and vulnerabilities.
- Addon Elements for Elementor (formerly Elementor Addon Elements)21 CVEs
- WP Mail Log9 CVEs
- Form Vibes – Database Manager for Forms5 CVEs
- Elementor Addon Elements5 CVEs
- form_vibes3 CVEs
- anywhere_elementor2 CVEs
- Dynific Addons for Elementor (formerly AnyWhere Elementor)2 CVEs
- Redirect 404 Error Page to Homepage or Custom Page with Logs2 CVEs
Common weakness types
The CWE weakness categories most often found in wpvibes CVEs. Follow any weakness for its full explanation.
- CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21 CVEs
- CWE-862Missing Authorization5 CVEs
- CWE-352Cross-Site Request Forgery (CSRF)4 CVEs
- CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3 CVEs
- CWE-200Exposure of Sensitive Information to an Unauthorized Actor1 CVE
- CWE-639Authorization Bypass Through User-Controlled Key1 CVE
- CWE-434Unrestricted Upload of File with Dangerous Type1 CVE
- CWE-201Insertion of Sensitive Information Into Sent Data1 CVE
CNAs that assign these CVEs
The CVE Numbering Authorities that publish wpvibes CVE records.
Disclosure activity by year
How many wpvibes CVEs were published each year.
Latest wpvibes CVEs
The most recently disclosed vulnerabilities affecting wpvibes.
- High · CVSS 7.1EPSS 0.2%2026-07-23
- High · CVSS 7.2EPSS 0.3%2026-07-11
- High · CVSS 7.1EPSS 0.3%2026-06-11
- Medium · CVSS 6.5EPSS 0.2%2026-02-26
- Medium · CVSS 4.9EPSS 0.3%2026-01-06
- Medium · CVSS 4.3EPSS 0.2%2026-01-05
- Medium · CVSS 6.4EPSS 0.2%2025-12-14
- Medium · CVSS 4.3EPSS 0.5%2025-01-15
- Medium · CVSS 4.3EPSS 0.3%2024-12-05
- High · CVSS 8.8EPSS 0.4%2024-11-01
- Medium · CVSS 6.3EPSS 0.4%2024-10-16
- Medium · CVSS 4.3EPSS 0.4%2024-10-12
Track new wpvibes CVEs as they are disclosed and get AI-written analysis and remediation guidance.
Monitor wpvibes CVEsOther vendors
Browse vulnerabilities for other tracked vendors.
Frequently asked questions
Common questions about wpvibes vulnerabilities.
- How many CVEs does wpvibes have?
- wpvibes has 46 published CVE records since 2021, including 8 in the last two years.
- How many wpvibes CVEs are in CISA KEV?
- None of wpvibes's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
- Which wpvibes products have the most CVEs?
- The wpvibes products with the most published CVEs are Addon Elements for Elementor (formerly Elementor Addon Elements), WP Mail Log, Form Vibes – Database Manager for Forms, Elementor Addon Elements, form_vibes.
- What are the most common weakness types in wpvibes CVEs?
- wpvibes's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-862 (Missing Authorization), CWE-352 (Cross-Site Request Forgery (CSRF)), CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).
- Are there public exploits for wpvibes vulnerabilities?
- Yes — 9 of wpvibes's CVEs have a known public exploit.
- How many critical wpvibes vulnerabilities are there?
- wpvibes has 1 critical and 14 high-severity CVEs.
- What is the average severity of wpvibes CVEs?
- The average CVSS base score across wpvibes's scored CVEs is 6.6.
References
- The MITRE CVE Program (opens in a new tab)
- Learn: What is a CVE?
- CWE directory: the weakness types these CVEs map to
- CNA directory: the CNAs that assign these CVEs
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Track wpvibes vulnerabilities
Monitor new wpvibes vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.