Vulnerability index

Browse CVEs

29 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gallery MEDIUM 5.4
CVE-2023-45631

Missing Authorization vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Exploiting Incorrectly Configured Access Control Secur…

Fix: after 2.0.3
Fix from $1,600 2025-01-02
Booking Calendar MEDIUM 6.5
CVE-2024-10856

The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the “wpdevart_booking_calendar” short…

Fix: 3.2.0+
Fix from $1,600 2024-12-24
Booking Calendar HIGH 8.8
CVE-2023-24407

Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control …

Fix: 3.2.4+
Fix from $1,950 2024-12-09
Organization Chart MEDIUM 5.4
CVE-2024-7355

The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in al…

Fix: 1.5.1+
Fix from $1,600 2024-08-07
Gallery MEDIUM 6.3
CVE-2024-37542

Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: f…

Fix: after 2.0.3
Fix from $1,600 2024-07-06
Gallery HIGH 8.8
CVE-2024-35750

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevart Responsive Image Gallery, Gallery Albu…

Fix: after 2.0.3
Fix from $1,950 2024-06-08
Booking Calendar CRITICAL 9.8
CVE-2023-24373

External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden…

Fix: 3.2.4+
Fix from $2,300 2024-06-03
Gallery MEDIUM 6.1
CVE-2024-30550

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Albu…

Fix: after 2.0.3
Fix from $1,600 2024-03-31
Gallery MEDIUM 5.4
CVE-2024-31120

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Albu…

Fix: after 2.0.3
Fix from $1,600 2024-03-31
Booking Calendar CRITICAL 9.8
CVE-2022-47428

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking …

Fix: 3.2.8+
Fix from $2,300 2023-11-06
Contact Form Builder MEDIUM 6.1
CVE-2023-46075

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Contact Form Builder, Contact Widget plugin <= 2.1.6 versions.

Fix: after 2.1.6
Fix from $1,600 2023-10-26
Gallery MEDIUM 6.1
CVE-2023-45630

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions.

Fix: after 2.0.3
Fix from $1,600 2023-10-18
Gallery Image And Video Gallery With Thumbnails HIGH 8.8
CVE-2023-45629

Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions.

Fix: after 2.0.3
Fix from $1,950 2023-10-16
Pricing Table Builder HIGH 7.2
CVE-2023-0900

The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leadin…

Fix: after 1.1.6
Fix from $1,950 2023-06-05
Image And Video Gallery With Thumbnails MEDIUM 6.1
CVE-2022-47603

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.1 versions.

Fix: 2.0.2+
Fix from $1,600 2023-03-29
Booking Calendar MEDIUM 5.4
CVE-2022-47438

Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions.

Fix: after 3.2.3
Fix from $1,600 2023-03-29
Responsive Vertical Icon Menu MEDIUM 5.4
CVE-2023-23983

Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 can lead to theme deletion.

Fix: 1.5.9+
Fix from $1,600 2023-02-28
Organization Chart HIGH 8.8
CVE-2023-24384

Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions.

Fix: after 1.4.4
Fix from $1,950 2023-02-23
Booking Calendar MEDIUM 5.4
CVE-2023-24388

Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin form…

Fix: 3.2.4+
Fix from $1,600 2023-02-17
Social Like Box And Page MEDIUM 5.4
CVE-2023-0177

The Social Like Box and Page by WpDevArt WordPress plugin before 0.8.41 does not validate and escape some of its shortcode attributes before outputti…

Fix: 0.8.41+
Fix from $1,600 2023-02-13
Booking Calendar CRITICAL 9.8
CVE-2022-3982

The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated us…

Fix: 3.2.2+
Fix from $2,300 2022-12-12
Gallery MEDIUM 6.1
CVE-2022-1946

The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (avail…

Fix: 2.0.0+
Fix from $1,600 2022-07-04
Pricing Table Builder MEDIUM 6.1
CVE-2022-0640

The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page,…

Fix: 1.1.5+
Fix from $1,600 2022-03-21
Coming Soon And Maintenance Mode MEDIUM 5.4
CVE-2021-24577

The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting ad…

Fix: 3.5.3+
Fix from $1,600 2021-10-11
Countdown And Countup\, Woocommerce Sales Timer HIGH 8.8
CVE-2021-34636

The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in…

Fix: after 1.5.7
Fix from $1,950 2021-09-28
Youtube Embed\, Playlist And Popup MEDIUM 5.4
CVE-2021-24464

The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, a…

Fix: 2.3.9+
Fix from $1,600 2021-08-02
Poll\, Survey\, Questionnaire And Voting System CRITICAL 9.8
CVE-2021-24442EPSS 46%

The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST paramete…

Fix: 1.5.3+
Fix from $2,300 2021-07-12
Booking Calendar HIGH 7.5
CVE-2018-10363

An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote a…

Mitigation only
Fix from $1,950 2018-06-13
Responsive Image Gallery Gallery Album CRITICAL 9.8
CVE-2017-14125

SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL comman…

Fix: after 1.2.0
Fix from $2,300 2017-09-25