WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in WP Extended – The Ultimate WordPress Toolkit

SMTP Email, Maintenance Mode, Duplicate Posts & Pages, Duplicate menu, Code Snippets, SVG File upload, Disable Gutenberg, Limit Login Attempts &am …

15Reported vulnerabilities
8.8Highest CVSS score
3.2.7Latest version
600+Active installs

What to do now

Update WP Extended – The Ultimate WordPress Toolkit to 3.2.5 or later. 15 of these have a fixed version available. Updating resolves them.

Plugin last updated: June 22, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-9347 Medium 6.1 0.5% Before 3.0.10
3.0.11 to 3.0.11 (inclusive)
3.0.12 to 3.0.12 (inclusive)
3.0.10 October 17, 2024
CVE-2024-11816 High 8.8 0.8% Before 3.0.12 3.0.12 January 8, 2025
CVE-2026-4314 High 8.8 0.3% 0 to 3.2.4 (inclusive) 3.2.5 March 22, 2026
CVE-2024-8102 High 8.8 0.5% Before 3.0.9 3.0.9 September 4, 2024
CVE-2024-13184 High 7.5 0.5% 0 to 3.0.12 (inclusive) 3.0.13 January 18, 2025
CVE-2025-30796 High 7.1 0.3% 0 to 3.0.14 (inclusive) 3.0.15 April 1, 2025
CVE-2024-47386 High 7.1 0.3% 0 to 3.0.8 (inclusive) 3.0.9 October 5, 2024
CVE-2024-8104 Medium 6.5 1.0% Before 3.0.9 3.0.9 September 4, 2024
CVE-2025-4963 Medium 6.4 0.3% 0 to 3.0.15 (inclusive) 3.0.16 May 28, 2025
CVE-2024-8106 Medium 6.5 0.5% Before 3.0.9 3.0.9 September 4, 2024
CVE-2024-37259 Medium 6.1 0.6% Before 3.0.0 3.0.0 July 22, 2024
CVE-2024-8119 Medium 6.1 0.4% Before 3.0.9 3.0.9 September 4, 2024
CVE-2024-8117 Medium 6.1 0.4% Before 3.0.9 3.0.9 September 4, 2024
CVE-2024-8123 Medium 5.4 0.3% Before 3.0.9 3.0.9 September 4, 2024
CVE-2024-8121 Medium 4.3 0.3% Before 3.0.9 3.0.9 September 4, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.