WPAMS - Apartment Management System for wordpress

WPAMS - Apartment Management System for wordpress has 9 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2026; 2 are fixed and 7 remain unpatched as of September 2026. Their average CVSS score is 7.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 4 high. 2025 was the busiest year with 7 disclosures.

The most common weakness is SQL Injection, behind 3 of the records (33%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type, Cross-Site Scripting.

2 of the records (22%) have a vendor fix, while 7 remain unpatched. The oldest unresolved one dates back to 2025.

4 independent researchers contributed these findings, most of them (5) reported by Thái An.

Strategic Overview

Avg CVSSHigh
7.8/ 10
Patch Coverage22%
Open

7

Fixed

2

Get automatic notifications for all WPAMS - Apartment Management System for wordpress vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2025-39401

WPAMS <= 44.0 (17-08-2023) - Unauthenticated Arbitrary File Upload

Read the full analysis

Vulnerability Records

9 records
2026-04-07 00:00CVE-2026-39433
4.3
Medium
Denver JacksonYes
2025-04-17 00:00CVE-2025-39401
9.8
Critical
Trương Hữu Phúc (truonghuuphuc)No
2025-04-17 00:00CVE-2025-39392
6.1
Medium
Thái AnNo
2025-04-17 00:00CVE-2025-39403
6.5
Medium
Thái AnNo
2025-04-17 00:00CVE-2025-39395
7.5
High
Thái AnNo
2025-04-17 00:00CVE-2025-39405
8.8
High
Thái AnNo
2025-04-17 00:00CVE-2025-39402
8.8
High
Trương Hữu Phúc (truonghuuphuc)No
2025-04-17 00:00CVE-2025-39406
9.8
Critical
Thái AnNo
2017-09-26 00:00CVE-2017-14847
8.8
High
Ihsan SencanYes
Showing 1–9 of 9 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C