Skip to content
Noroxi

wpdevart records

41 published records for vendor wpdevart.

All records

41 records
  • Poll, Survey, Questionnaire and Voting system < 1.5.3 - Unauthenticated Blind SQL Injection

    CriticalCVSS 9.8Proof of conceptEPSS 46%

    wpdevart · poll\, survey\, questionnaire and voting systemJul 12, 2021

  • Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    wpdevart · booking calendarDec 12, 2022

  • SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary S

    CriticalCVSS 9.8No exploitEPSS 3%

    wpdevart · responsive image gallery gallery albumSep 25, 2017

  • WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.7 is vulnerable to SQL Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    wpdevart · booking calendarNov 6, 2023

  • WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    wpdevart · booking calendarJun 3, 2024

  • Countdown and CountUp, WooCommerce Sales Timer <= 1.5.7 Cross-Site Request Forgery to Stored Cross-Site Scripting

    HighCVSS 8.8No exploitEPSS 1%

    wpdevart · countdown and countup\, woocommerce sales timerSep 28, 2021

  • WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    wpdevart · booking calendarDec 9, 2024

  • WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - SQL Injection vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    wpdevart · galleryJun 8, 2024

  • WordPress Organization chart Plugin <= 1.4.4 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    wpdevart · organization chartFeb 23, 2023

  • WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    wpdevart · gallery - image and video gallery with thumbnailsOct 16, 2023

  • An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress.

    HighCVSS 7.5No exploitEPSS 1%

    wpdevart · booking calendarJun 13, 2018

  • CVE-2023-0900
    29Monitor

    AP Pricing Tables Lite <= 1.1.6 - Admin+ SQLi

    HighCVSS 7.2Proof of conceptEPSS 3%

    wpdevart · pricing table builderJun 5, 2023

  • CVE-2024-9504
    28Monitor

    Booking calendar, Appointment Booking System <= 3.2.15 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload

    HighCVSS 7.2No exploitEPSS 0%

    wpdevart · booking calendar, appointment booking systemNov 26, 2024

  • Booking Calendar WpDevArt <= 3.2.19 - Authenticated (Contributor+) SQL Injection

    MediumCVSS 6.5No exploitEPSS 0%

    wpdevart · booking calendarDec 24, 2024

  • CVE-2022-1946
    25Monitor

    Gallery < 2.0.0 - Reflected Cross-Site Scripting

    MediumCVSS 6.1Proof of conceptEPSS 2%

    wpdevart · galleryJul 4, 2022

  • WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerability

    MediumCVSS 6.3No exploitEPSS 0%

    wpdevart · galleryJul 6, 2024

  • CVE-2022-0640
    24Monitor

    AP Pricing Tables Lite < 1.1.5 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    wpdevart · pricing table builderMar 21, 2022

  • WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    wpdevart · image and video gallery with thumbnailsMar 29, 2023

  • WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    wpdevart · galleryMar 31, 2024

  • WordPress Contact Form Builder, Contact Widget Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    wpdevart · contact form builderOct 26, 2023

  • WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    wpdevart · galleryOct 18, 2023

  • YouTube Embed, Playlist and Popup < 2.3.9 - Contributor+ Stored XSS

    MediumCVSS 5.4No exploitEPSS 1%

    wpdevart · youtube embed\, playlist and popupAug 2, 2021

  • Coming Soon and Maintenance Mode < 3.5.3 - Authenticated Stored XSS

    MediumCVSS 5.4No exploitEPSS 1%

    wpdevart · coming soon and maintenance modeOct 11, 2021

  • CVE-2023-0177
    21Monitor

    Social Like Box and Page by WpDevArt < 0.8.41 - Contributor+ Stored XSS

    MediumCVSS 5.4No exploitEPSS 0%

    wpdevart · social like box and pageFeb 13, 2023

  • WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    wpdevart · galleryMar 31, 2024