Other
3 records60%First: 2025. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 5 vulnerability records associated with WHMpress - WHMCS WordPress Integration Plugin, published between 2024 and 2025.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
Use this history
A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.
| Year | Records | Relative volume |
|---|---|---|
| 2024 | 2 | |
| 2025 | 3 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 40% |
| High | 1 | 20% |
| Medium | 2 | 40% |
First: 2025. Latest: 2025.
First: 2024. Latest: 2024.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
6.3-revision-1Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
* - 6.2-revision-9 | WHMpress <= 6.2-revision-9 - Authenticated (Contributor+) Local File Inclusion | May 16, 2025 | Not supplied | High |
* - 6.2-revision-9 | WHMpress <= 6.2-revision-9 - Unauthenticated Local File Inclusion | May 16, 2025 | Not supplied | Critical |
* - 6.3-revision-0 | WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update | February 27, 2025 | 6.3-revision-1 | Critical |
* - 6.2-revision-5 | WHMpress <= 6.2-revision-5 - Missing Authorization to Authenticated (Subscriber+) Settings Update | August 12, 2024 | Not supplied | Medium |
* - 6.2-revision-5 | WHMpress <= 6.2-revision-5 - Reflected Cross-Site Scripting | August 12, 2024 | Not supplied | Medium |
Selected source records
Published: May 16, 2025
Published: May 16, 2025
Published: February 27, 2025
Published: August 12, 2024
Published: August 12, 2024
Published: February 27, 2025
Published: May 16, 2025
Published: May 16, 2025
Published: August 12, 2024
Published: August 12, 2024
Published: May 16, 2025
Published: May 16, 2025
Published: August 12, 2024
Published: August 12, 2024
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.