Verified Security Impact

Impact Ledger

Observed security remediation outcomes powered by WPAuditLab

A public, privacy-preserving proof-of-work page showing remediation outcomes observed by WPAuditLab — without exposing customer names, private URLs, exploit payloads, reproduction detail, or unresolved vulnerability specifics.

Last updated: July 21, 2026 6:10 pm
165Reports PublishedCustomer-ready security reports generated.
61High-Risk ReportsCritical and high severity reports.
36Findings RemediatedObserved by retest, not raw scan noise.
44Assets AuditedDistinct plugins or projects represented.
1.4M+Install ReachApproximate active installs represented.
7.3Avg. Remediated CVSSAverage severity of fixed findings.

How this ledger works

The ledger is generated from the WPAuditLab validation and retest workflow, then heavily constrained to public-safe, non-actionable metadata.

  • Only finalized reports are shown.
  • Only findings marked remediated, resolved, or closed by the workflow are included.
  • Customer domains, private URLs, payloads, and unresolved issues are omitted.
  • Metrics come from validated finding and remediation timestamps.
  • Install counts are manually curated public estimates and may be rounded.

Why this matters

Security programs should reduce real product risk, not just produce reports. This page gives buyers, vendors, agencies, and engineers a privacy-preserving signal that WPAuditLab finds issues and tracks remediation without publishing exploit-enabling detail.

  • Outcome-oriented evidence for stakeholders.
  • Responsible disclosure posture by default.
  • Minimal metadata instead of exploit detail.

Remediation Impact Ledger

Short, public-safe remediation metadata, including when WPAuditLab found and marked each issue remediated. Sensitive technical details are intentionally withheld.

Premium Addons for Elementor4.11.87Install count: 700,000+CWE-2007.5June 12, 2026July 21, 2026View ▾
HighData Exposure / IDORJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classData Exposure / IDOR
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Points and Rewards for WooCommerce2.10.2Install count: 7,000+CWE-8624.3June 9, 2026July 20, 2026View ▾
MediumIDOR / Missing AuthorizationJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classIDOR / Missing Authorization
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Points and Rewards for WooCommerce2.10.2Install count: 7,000+CWE-8628.1June 9, 2026July 20, 2026View ▾
HighIDOR / Missing Authorization / Business…Jul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classIDOR / Missing Authorization / Business…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Points and Rewards for WooCommerce2.10.2Install count: 7,000+CWE-8628.1June 8, 2026July 20, 2026View ▾
HighMissing AuthorizationJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classMissing Authorization
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Kirki6.0.14Install count: 500,000+CWE-8627.5June 23, 2026July 20, 2026View ▾
HighMissing Authorization / IDOR / Data…Jul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classMissing Authorization / IDOR / Data…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Kirki6.0.14Install count: 500,000+CWE-8627.1June 23, 2026July 20, 2026View ▾
HighIDOR / Missing Authorization / Data…Jul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classIDOR / Missing Authorization / Data…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS Assignments2.6.2CWE-8628.1June 7, 2026July 19, 2026View ▾
HighIDOR / Missing AuthorizationJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classIDOR / Missing Authorization
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS Assignments2.6.2CWE-6397.1June 7, 2026July 19, 2026View ▾
HighIDOR / Missing Authorization / Data…Jul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classIDOR / Missing Authorization / Data…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS Groups1.4.0CWE-9158.1June 7, 2026July 19, 2026View ▾
HighMass Assignment / IDORJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classMass Assignment / IDOR
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Customer Plugin — RedactedCWE-8626.5June 17, 2026July 18, 2026View ▾
MediumMissing Authorization / Data ExposureJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classMissing Authorization / Data Exposure
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Kirki6.0.14Install count: 500,000+CWE-8625.4June 23, 2026July 16, 2026View ▾
MediumMissing Authorization / Data ExposureJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classMissing Authorization / Data Exposure
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Ultimate Member2.12.1Install count: 200,000+CWE-8628.8June 8, 2026July 13, 2026View ▾
HighIDOR / Missing AuthorizationJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classIDOR / Missing Authorization
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Ultimate Member2.12.1Install count: 200,000+CWE-8628.8June 8, 2026July 13, 2026View ▾
HighPrivilege Escalation / Missing AuthorizationJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classPrivilege Escalation / Missing Authorization
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Customer Plugin — RedactedCWE-8625.4June 25, 2026July 11, 2026View ▾
MediumMissing Authorization / IDORJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classMissing Authorization / IDOR
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
CURCY - WooCommerce Multi Currency Premium2.3.6CWE-8628.1June 8, 2026July 8, 2026View ▾
HighIDOR / Missing Authorization / Mass…Jul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classIDOR / Missing Authorization / Mass…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Customer Plugin — RedactedCWE-8625.4July 1, 2026July 4, 2026View ▾
MediumMissing Authorization / Improper Access ControlJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classMissing Authorization / Improper Access Control
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Customer Plugin — RedactedCWE-2007.5July 1, 2026July 1, 2026View ▾
HighSensitive Data Exposure / Missing Access…Jul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classSensitive Data Exposure / Missing Access…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Customer Plugin — RedactedCWE-8628.1June 25, 2026July 1, 2026View ▾
HighIDOR / Missing AuthorizationJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classIDOR / Missing Authorization
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Customer Plugin — RedactedCWE-8625.4June 26, 2026July 1, 2026View ▾
MediumMissing Authorization / IDORJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classMissing Authorization / IDOR
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Customer Plugin — RedactedCWE-2007.5June 26, 2026July 1, 2026View ▾
HighSensitive Data Exposure / Missing AuthorizationJul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classSensitive Data Exposure / Missing Authorization
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Customer Plugin — RedactedCWE-8626.5June 26, 2026July 1, 2026View ▾
MediumIDOR / Missing Authorization / Information…Jul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classIDOR / Missing Authorization / Information…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Customer Plugin — RedactedCWE-2006.5July 1, 2026July 1, 2026View ▾
MediumSensitive Data Exposure / Missing Access…Jul 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classSensitive Data Exposure / Missing Access…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS Groups1.4.0CWE-6397.1June 7, 2026June 23, 2026View ▾
HighBroken Object Authorization / REST Invitation…Jun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classBroken Object Authorization / REST Invitation…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS Groups1.4.0CWE-3627.1June 7, 2026June 23, 2026View ▾
HighRace Condition / TOCTOU / Paid…Jun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classRace Condition / TOCTOU / Paid…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS Groups1.4.0CWE-6398.1June 7, 2026June 23, 2026View ▾
HighBroken Object Authorization / Business Logic…Jun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classBroken Object Authorization / Business Logic…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS Groups1.4.0CWE-3628.2June 7, 2026June 23, 2026View ▾
HighRace Condition / TOCTOU / Paid…Jun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classRace Condition / TOCTOU / Paid…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Paid Memberships Pro - Roles Add On1.5.1CWE-8628.8June 7, 2026June 12, 2026View ▾
HighBroken Access Control / Privilege EscalationJun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classBroken Access Control / Privilege Escalation
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Paid Memberships Pro - Roles Add On1.5.1CWE-2695.7June 7, 2026June 12, 2026View ▾
MediumInsecure Cleanup / Privilege RetentionJun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classInsecure Cleanup / Privilege Retention
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
Paid Memberships Pro - Roles Add On1.5.1CWE-8628.8June 7, 2026June 12, 2026View ▾
HighMissing Authorization / Mass Assignment /…Jun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classMissing Authorization / Mass Assignment /…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS10.0.10Install count: 10,000+CWE-8628.1June 6, 2026June 7, 2026View ▾
HighMissing Authorization / API Key Owner…Jun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classMissing Authorization / API Key Owner…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS10.0.10Install count: 10,000+CWE-2006.5June 6, 2026June 7, 2026View ▾
MediumSensitive Data Exposure / Missing AuthorizationJun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classSensitive Data Exposure / Missing Authorization
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS10.0.10Install count: 10,000+CWE-8628.1June 6, 2026June 7, 2026View ▾
HighMissing Authorization / Object Relationship AbuseJun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classMissing Authorization / Object Relationship Abuse
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS10.0.10Install count: 10,000+CWE-748.1June 6, 2026June 7, 2026View ▾
HighInjection / Improper Input NeutralizationJun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classInjection / Improper Input Neutralization
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS10.0.10Install count: 10,000+CWE-6397.1June 7, 2026June 7, 2026View ▾
HighBroken Object Authorization / IDOR /…Jun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classBroken Object Authorization / IDOR /…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS10.0.10Install count: 10,000+CWE-6396.5June 7, 2026June 7, 2026View ▾
MediumBroken Object Authorization / IDOR /…Jun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classBroken Object Authorization / IDOR /…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.
LifterLMS10.0.10Install count: 10,000+CWE-8627.1June 7, 2026June 7, 2026View ▾
HighBroken Object Authorization / IDOR in…Jun 2026Remediation observed

Technical details withheld pending safe disclosure review

Finding classBroken Object Authorization / IDOR in…
Public detailWithheld to avoid exposing actionable vulnerability detail.
Workflow statusMarked remediated by WPAuditLab remediation/retest workflow.
Sensitive identifiers, private URLs, exploit payloads, reproduction steps, and fix guidance are withheld by design. Public detail may expand only after safe disclosure review.