Skip to main content

Vendor archive

wpdevart CVEs

Beta · best-effort

40 CVEs tagged to vendor wpdevart3 Critical, 7 High, 28 Medium, 2 Low, 0 Unrated.

CVE-2023-0177

Published Feb 13, 2023

The Social Like Box and Page by WpDevArt WordPress plugin before 0.8.41 does not validate and escape some of its shortcode attributes before outputting them back in a page/post wh…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3982

Published Dec 12, 2022

The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-1946

Published Jul 4, 2022

The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0876

Published Apr 25, 2022

The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scriptin…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0640

Published Mar 21, 2022

The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0199

Published Feb 21, 2022

The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25075

Published Feb 21, 2022

The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX actio…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-24577

Published Oct 11, 2021

The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24464

Published Aug 2, 2021

The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10363

Published Jun 13, 2018

An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the val…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-40 of 40 CVEsPage 2 of 2