wpdevart records
41 published records for vendor wpdevart.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 31.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-352 Cross-Site Request Forgery (CSRF)7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-862 Missing Authorization4
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-472 External Control of Assumed-Immutable Web Parameter1
The weakness classes this vendor ships most often: where to look.
CWEAll records
41 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
53Plan | CVE-2021-24442Proof of concept | Poll, Survey, Questionnaire and Voting system < 1.5.3 - Unauthenticated Blind SQL Injectionwpdevart · poll\, survey\, questionnaire and voting system · CWE-89 | Critical9.8 | — | 46.0% | Jul 12, 2021 |
40Plan | CVE-2022-3982Proof of concept | Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Uploadwpdevart · booking calendar · CWE-434 | Critical9.8 | — | 4.5% | Dec 12, 2022 |
40Plan | CVE-2017-14125No exploit | SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary Swpdevart · responsive image gallery gallery album · CWE-89 | Critical9.8 | — | 3.2% | Sep 25, 2017 |
39Monitor | CVE-2022-47428No exploit | WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.7 is vulnerable to SQL Injectionwpdevart · booking calendar · CWE-89 | Critical9.8 | — | 0.7% | Nov 6, 2023 |
39Monitor | CVE-2023-24373No exploit | WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerabilitywpdevart · booking calendar · CWE-472 | Critical9.8 | — | 0.4% | Jun 3, 2024 |
35Monitor | CVE-2021-34636No exploit | Countdown and CountUp, WooCommerce Sales Timer <= 1.5.7 Cross-Site Request Forgery to Stored Cross-Site Scriptingwpdevart · countdown and countup\, woocommerce sales timer · CWE-352 | High8.8 | — | 0.6% | Sep 28, 2021 |
35Monitor | CVE-2023-24407No exploit | WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Broken Access Control vulnerabilitywpdevart · booking calendar · CWE-862 | High8.8 | — | 0.5% | Dec 9, 2024 |
35Monitor | CVE-2024-35750No exploit | WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - SQL Injection vulnerabilitywpdevart · gallery · CWE-89 | High8.8 | — | 0.4% | Jun 8, 2024 |
35Monitor | CVE-2023-24384No exploit | WordPress Organization chart Plugin <= 1.4.4 is vulnerable to Cross Site Request Forgery (CSRF)wpdevart · organization chart · CWE-352 | High8.8 | — | 0.3% | Feb 23, 2023 |
35Monitor | CVE-2023-45629No exploit | WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Request Forgery (CSRF)wpdevart · gallery - image and video gallery with thumbnails · CWE-352 | High8.8 | — | 0.2% | Oct 16, 2023 |
30Monitor | CVE-2018-10363No exploit | An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress.wpdevart · booking calendar · CWE-20 | High7.5 | — | 1.4% | Jun 13, 2018 |
29Monitor | CVE-2023-0900Proof of concept | AP Pricing Tables Lite <= 1.1.6 - Admin+ SQLiwpdevart · pricing table builder · CWE-89 | High7.2 | — | 3.2% | Jun 5, 2023 |
28Monitor | CVE-2024-9504No exploit | Booking calendar, Appointment Booking System <= 3.2.15 - Unauthenticated Stored Cross-Site Scripting via SVG File Uploadwpdevart · booking calendar, appointment booking system · CWE-434 | High7.2 | — | 0.5% | Nov 26, 2024 |
26Monitor | CVE-2024-10856No exploit | Booking Calendar WpDevArt <= 3.2.19 - Authenticated (Contributor+) SQL Injectionwpdevart · booking calendar · CWE-89 | Medium6.5 | — | 0.5% | Dec 24, 2024 |
25Monitor | CVE-2022-1946Proof of concept | Gallery < 2.0.0 - Reflected Cross-Site Scriptingwpdevart · gallery · CWE-79 | Medium6.1 | — | 1.8% | Jul 4, 2022 |
25Monitor | CVE-2024-37542No exploit | WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerabilitywpdevart · gallery · CWE-862 | Medium6.3 | — | 0.2% | Jul 6, 2024 |
24Monitor | CVE-2022-0640No exploit | AP Pricing Tables Lite < 1.1.5 - Reflected Cross-Site Scriptingwpdevart · pricing table builder · CWE-79 | Medium6.1 | — | 0.9% | Mar 21, 2022 |
24Monitor | CVE-2022-47603No exploit | WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS)wpdevart · image and video gallery with thumbnails · CWE-79 | Medium6.1 | — | 0.4% | Mar 29, 2023 |
24Monitor | CVE-2024-30550No exploit | WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) vulnerabilitywpdevart · gallery · CWE-79 | Medium6.1 | — | 0.4% | Mar 31, 2024 |
24Monitor | CVE-2023-46075No exploit | WordPress Contact Form Builder, Contact Widget Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS)wpdevart · contact form builder · CWE-79 | Medium6.1 | — | 0.3% | Oct 26, 2023 |
24Monitor | CVE-2023-45630No exploit | WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)wpdevart · gallery · CWE-79 | Medium6.1 | — | 0.3% | Oct 18, 2023 |
21Monitor | CVE-2021-24464No exploit | YouTube Embed, Playlist and Popup < 2.3.9 - Contributor+ Stored XSSwpdevart · youtube embed\, playlist and popup · CWE-79 | Medium5.4 | — | 0.6% | Aug 2, 2021 |
21Monitor | CVE-2021-24577No exploit | Coming Soon and Maintenance Mode < 3.5.3 - Authenticated Stored XSSwpdevart · coming soon and maintenance mode · CWE-79 | Medium5.4 | — | 0.6% | Oct 11, 2021 |
21Monitor | CVE-2023-0177No exploit | Social Like Box and Page by WpDevArt < 0.8.41 - Contributor+ Stored XSSwpdevart · social like box and page · CWE-79 | Medium5.4 | — | 0.5% | Feb 13, 2023 |
21Monitor | CVE-2024-31120No exploit | WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerabilitywpdevart · gallery · CWE-79 | Medium5.4 | — | 0.4% | Mar 31, 2024 |
- CVE-2021-2444253Plan
Poll, Survey, Questionnaire and Voting system < 1.5.3 - Unauthenticated Blind SQL Injection
CriticalCVSS 9.8Proof of conceptEPSS 46%wpdevart · poll\, survey\, questionnaire and voting systemJul 12, 2021
- CVE-2022-398240Plan
Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload
CriticalCVSS 9.8Proof of conceptEPSS 5%wpdevart · booking calendarDec 12, 2022
- CVE-2017-1412540Plan
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary S
CriticalCVSS 9.8No exploitEPSS 3%wpdevart · responsive image gallery gallery albumSep 25, 2017
- CVE-2022-4742839Monitor
WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.7 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%wpdevart · booking calendarNov 6, 2023
- CVE-2023-2437339Monitor
WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability
CriticalCVSS 9.8No exploitEPSS 0%wpdevart · booking calendarJun 3, 2024
- CVE-2021-3463635Monitor
Countdown and CountUp, WooCommerce Sales Timer <= 1.5.7 Cross-Site Request Forgery to Stored Cross-Site Scripting
HighCVSS 8.8No exploitEPSS 1%wpdevart · countdown and countup\, woocommerce sales timerSep 28, 2021
- CVE-2023-2440735Monitor
WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 1%wpdevart · booking calendarDec 9, 2024
- CVE-2024-3575035Monitor
WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - SQL Injection vulnerability
HighCVSS 8.8No exploitEPSS 0%wpdevart · galleryJun 8, 2024
- CVE-2023-2438435Monitor
WordPress Organization chart Plugin <= 1.4.4 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%wpdevart · organization chartFeb 23, 2023
- CVE-2023-4562935Monitor
WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%wpdevart · gallery - image and video gallery with thumbnailsOct 16, 2023
- CVE-2018-1036330Monitor
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress.
HighCVSS 7.5No exploitEPSS 1%wpdevart · booking calendarJun 13, 2018
- CVE-2023-090029Monitor
AP Pricing Tables Lite <= 1.1.6 - Admin+ SQLi
HighCVSS 7.2Proof of conceptEPSS 3%wpdevart · pricing table builderJun 5, 2023
- CVE-2024-950428Monitor
Booking calendar, Appointment Booking System <= 3.2.15 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload
HighCVSS 7.2No exploitEPSS 0%wpdevart · booking calendar, appointment booking systemNov 26, 2024
- CVE-2024-1085626Monitor
Booking Calendar WpDevArt <= 3.2.19 - Authenticated (Contributor+) SQL Injection
MediumCVSS 6.5No exploitEPSS 0%wpdevart · booking calendarDec 24, 2024
- CVE-2022-194625Monitor
Gallery < 2.0.0 - Reflected Cross-Site Scripting
MediumCVSS 6.1Proof of conceptEPSS 2%wpdevart · galleryJul 4, 2022
- CVE-2024-3754225Monitor
WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerability
MediumCVSS 6.3No exploitEPSS 0%wpdevart · galleryJul 6, 2024
- CVE-2022-064024Monitor
AP Pricing Tables Lite < 1.1.5 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%wpdevart · pricing table builderMar 21, 2022
- CVE-2022-4760324Monitor
WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%wpdevart · image and video gallery with thumbnailsMar 29, 2023
- CVE-2024-3055024Monitor
WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%wpdevart · galleryMar 31, 2024
- CVE-2023-4607524Monitor
WordPress Contact Form Builder, Contact Widget Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%wpdevart · contact form builderOct 26, 2023
- CVE-2023-4563024Monitor
WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%wpdevart · galleryOct 18, 2023
- CVE-2021-2446421Monitor
YouTube Embed, Playlist and Popup < 2.3.9 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%wpdevart · youtube embed\, playlist and popupAug 2, 2021
- CVE-2021-2457721Monitor
Coming Soon and Maintenance Mode < 3.5.3 - Authenticated Stored XSS
MediumCVSS 5.4No exploitEPSS 1%wpdevart · coming soon and maintenance modeOct 11, 2021
- CVE-2023-017721Monitor
Social Like Box and Page by WpDevArt < 0.8.41 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 0%wpdevart · social like box and pageFeb 13, 2023
- CVE-2024-3112021Monitor
WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%wpdevart · galleryMar 31, 2024