Known vulnerabilities in WPMasterToolKit (WPMTK) – All in one plugin
Duplicate post, post order, email via SMTP, code snippets, disable gutenberg, child theme generator, svg support, disable XMLRPC, and more...
5Reported vulnerabilities
7.2Highest CVSS score
2.22.0Latest version
5,000+Active installs
What to do now
Update WPMasterToolKit (WPMTK) – All in one plugin to 2.14.1 or later.
5 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2024-56249 | High | 1.3% | 1.13.1 and earlier | 1.14.0 |
December 30, 2024 |
| CVE-2025-3300 | High | 0.9% | 0 to 1.15.0 (inclusive) | 2.6.0 |
April 24, 2025 |
| CVE-2025-14166 | Medium | 0.5% | 0 to 2.13.0 (inclusive) | 2.13.1 |
December 12, 2025 |
| CVE-2024-56248 | Medium | 0.5% | 1.13.1 and earlier | 1.14.0 |
December 30, 2024 |
| CVE-2026-24388 | Medium | 0.2% | 2.14.0 and earlier | 2.14.1 |
January 15, 2026 |