liquidweb CVE Vulnerabilities & Metrics

Focus on liquidweb vulnerabilities and metrics.

Last updated: 15 Feb 2026, 23:25 UTC

About liquidweb Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with liquidweb. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total liquidweb CVEs: 9
Earliest CVE date: 08 Sep 2019, 23:15 UTC
Latest CVE date: 16 Jan 2026, 10:16 UTC

Latest CVE reference: CVE-2025-14844

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): -66.67%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): -66.67%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical liquidweb CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.72

Max CVSS: 6.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 8
4.0-6.9 1
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS liquidweb CVEs

These are the five CVEs with the highest CVSS scores for liquidweb, sorted by severity first and recency.

All CVEs for liquidweb

CVE-2025-14844 liquidweb vulnerability CVSS: 0 16 Jan 2026, 10:16 UTC

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup_intent_for_saved_card' function due to missing capability check. Additionally, the plugin does not check a user-controlled key, which makes it possible for unauthenticated attackers to leak Stripe SetupIntent client_secret values for any membership.

CVE-2024-11090 liquidweb vulnerability CVSS: 0 26 Jan 2025, 07:15 UTC

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.

CVE-2024-1319 liquidweb vulnerability CVSS: 0 04 Mar 2024, 21:15 UTC

The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).

CVE-2024-1316 liquidweb vulnerability CVSS: 0 04 Mar 2024, 21:15 UTC

The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events).

CVE-2023-47668 liquidweb vulnerability CVSS: 0 23 Nov 2023, 00:15 UTC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions.

CVE-2023-3182 liquidweb vulnerability CVSS: 0 17 Jul 2023, 14:15 UTC

The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2022-45825 liquidweb vulnerability CVSS: 0 28 Mar 2023, 08:15 UTC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions.

CVE-2022-4759 liquidweb vulnerability CVSS: 0 13 Feb 2023, 15:15 UTC

The GigPress WordPress plugin before 2.3.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2019-16120 liquidweb vulnerability CVSS: 6.5 08 Sep 2019, 23:15 UTC

CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.