Skip to main content

Vendor archive

wpdevart CVEs

Beta · best-effort

40 CVEs tagged to vendor wpdevart3 Critical, 7 High, 28 Medium, 2 Low, 0 Unrated.

CVE-2023-45631

Published Jan 2, 2025

Missing Authorization vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-10856

Published Dec 24, 2024

The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the “wpdevart_booking_calendar” shortcode in versions up to, and in…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-24407

Published Dec 9, 2024

Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7355

Published Aug 7, 2024

The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in all versions up to, and includin…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37542

Published Jul 6, 2024

Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35750

Published Jun 8, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevart Responsive Image Gallery, Gallery Album.This issue affects Responsiv…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-24373

Published Jun 3, 2024

External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Boo…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30550

Published Mar 31, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Reflected XSS.This is…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31120

Published Mar 31, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Stored XSS.This issue…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-47428

Published Nov 6, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.Th…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-46075

Published Oct 26, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Contact Form Builder, Contact Widget plugin <= 2.1.6 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-45630

Published Oct 18, 2023

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-0900

Published Jun 5, 2023

The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitab…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-24387

Published Apr 6, 2023

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart Organization chart plugin <= 1.4.4 versions.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-47438

Published Mar 29, 2023

Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24388

Published Feb 17, 2023

Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin forms actions (create, duplicate,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 40 CVEsPage 1 of 2