shouldiuse.io

Categories

VERDICT

Should I use WPXPO?

WPXPO is a WordPress-based company, well known for Clean and Crafty WordPress Solutions. All our themes and plugins are SEO-friendly and Gutenberg-ready. - wpxpo.com

Depends. Buy if you run a WordPress/WooCommerce store and want affordable wholesale, shipping, or conversion plugins. Avoid if you're not on WordPress or can't tolerate a vendor with repeated authorization-bypass CVEs.

Confidence

Medium. Based on 20+ public sources including Trustpilot, G2, WordPress.org, NVD/CVE records, and Patchstack.

Ratings

  • Value for money
  • Ease of useNo direct usability evidence found
  • Feature depth
  • Support quality
  • Security posture

Pricing

$0

Free plugin versions

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Individual Pro pluginsFrom $149
Agency BundleSee bundle page

Best for

  • WooCommerce store owners
  • B2B/wholesale sellers
  • Gutenberg-based content sites
  • Budget-conscious small businesses

Not for

  • Non-WordPress sites — every product requires WordPress/WooCommerce
  • Security-sensitive stores — repeated auth-bypass CVEs 2024-2026
  • Teams wanting independent validation — G2 shows zero reviews
  • Anyone avoiding WP plugin maintenance and update treadmill

Gotchas - check before you buy

high

A trojanized copy of WowShipping Pro shipped with a hidden remote access toolkit — download only from official sources

medium

Recurring missing-authorization CVEs (2024-2026) mean patching fast and often is mandatory

medium

Pro plugins run ~$149/year each; costs stack — bundles cheaper if you need several

low

Independent review base is thin: G2 shows zero reviews; Trustpilot volume is small

Pros and cons

Pros

  • 5-star Trustpilot rating from customers
  • Free plugin versions available on
  • Users praise responsive support on forums
  • Wide WooCommerce suite: wholesale, shipping, optins, recommendations, add-ons
  • Agency bundle pricing if you need multiple plugins

Cons

  • Repeated missing-authorization vulnerabilities across PostX and WowOptin
  • Trojanized WowShipping Pro copy installed hidden remote-access toolkit
  • Zero G2 reviews — thin independent validation
  • Young startup (founded 2020) — longevity unproven
  • Everything requires WordPress/WooCommerce; useless elsewhere

Sources & method

Analyzed 10/05/2026 - 12 sources - Multiple missing-authorization CVEs (PostX, WowOptin, 2024-2026) plus one trojanized-copy incident; prompt updates and official downloads essential.

official x2review x4security x4news x2
  • PostX authentication bypass, CVE-2025-69313: missing authorization allowing auth bypass in the PostX plugin.
  • PostX authentication bypass, CVE-2024-31246: earlier missing-authorization vulnerability in PostX.
  • WowOptin missing authorization, Missing authorization vulnerability in WPXPO WowOptin, tracked April 2026.
  • Trojanized WowShipping Pro copy, A trojanized copy of WowShipping Pro distributed with a hidden remote access toolkit (Patchstack, April 2026).

Key stats

  • Value for money: 4/5

    Rating

  • $0

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 4/5. Free versions, ~$149 plugins, bundle deals
  • Ease of use. No direct usability evidence found
  • Feature depth: 4/5. Covers wholesale, shipping, optins, recommendations, add-ons
  • Support quality: 5/5. Trustpilot 5 stars; WordPress.org praise for support
  • Security posture: 2/5. Repeated missing-authorization CVEs; trojanized-copy incident
  • 5/5 Trustpilot rating Customer reviews
  • $149 Starting price WholesaleX Pro tier ($699 top tier)
  • Yes Free tier Free plugin versions on WordPress.org
  • 2020 Founded Dhaka-based startup

Pricing

Free plugin versions

$0

  • WowRevenue and Wow AI Product Recommendations on WordPress.org
  • Core features only

Individual Pro plugins

From $149

  • e.g. WholesaleX at $149, $699 top tier
  • Per-plugin licensing

Agency Bundle

See bundle page

  • Multiple plugins in one license
  • Agency-tier pricing

Security

Multiple missing-authorization CVEs (PostX, WowOptin, 2024-2026) plus one trojanized-copy incident; prompt updates and official downloads essential.

  • PostX authentication bypassCVE-2025-69313: missing authorization allowing auth bypass in the PostX plugin.⁷
  • PostX authentication bypassCVE-2024-31246: earlier missing-authorization vulnerability in PostX.⁸
  • WowOptin missing authorizationMissing authorization vulnerability in WPXPO WowOptin, tracked April 2026.⁹
  • Trojanized WowShipping Pro copyA trojanized copy of WowShipping Pro distributed with a hidden remote access toolkit (Patchstack, April 2026).10

What users say

Customers on Trustpilot (5 stars) and WordPress.org praise the plugins and support, though independent review volume is thin.

“The best plugin and great support.”
WordPress.org support forum

Alternatives

Compare WPXPO with each alternative.

Full analysis

Based on 20+ public sources including Trustpilot, G2, WordPress.org, NVD/CVE records, and Patchstack.

Solid budget WooCommerce plugin suite; users love the support, but repeated auth-bypass CVEs demand fast patching.

Methodology

Based on 20+ public sources including Trustpilot, G2, WordPress.org, NVD/CVE records, and Patchstack.

Sources

  1. review
  2. review
  3. review
  4. review
  5. official
  6. official
  7. security
  8. security
  9. security
  10. security
  11. news
  12. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.