VYPR

Vendor CVEs

Wpdevart

All CVEs

64 total · sorted by risk
  • CVE-2024-10027MedNov 7, 2024
    risk 0.31cvss 4.8epss 0.00

    The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for…

  • CVE-2022-34656MedSep 6, 2022
    risk 0.31cvss 4.8epss 0.00

    Authenticated (admin+) Cross-Site Scripting (XSS) vulnerability in wpdevart Poll, Survey, Questionnaire and Voting system plugin <= 1.7.4 at WordPress.

  • CVE-2022-0876MedApr 25, 2022
    risk 0.31cvss 4.8epss 0.01

    The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed

  • CVE-2018-5672MedJan 13, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label] parameter.

  • CVE-2018-5671MedJan 13, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][price_percent] parameter.

  • CVE-2018-5670MedJan 13, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_conditions[count][] parameter.

  • CVE-2024-9306MedOct 4, 2024
    risk 0.29cvss 4.4epss 0.00

    The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2023-45631MedJan 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

  • CVE-2023-24384MedFeb 23, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions.

  • CVE-2023-24388MedFeb 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin forms actions (create, duplicate, edit, delete).

  • CVE-2022-0199MedFeb 21, 2022
    risk 0.28cvss 4.3epss 0.00

    The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack

  • CVE-2023-24373LowJun 3, 2024
    risk 0.24cvss 3.7epss 0.00

    External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.

  • CVE-2021-25075LowFeb 21, 2022
    risk 0.23cvss 3.5epss 0.02

    The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings,…

  • CVE-2022-0164MedFeb 21, 2022
    risk 0.21cvss 4.3epss 0.00

    The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users

Page 2 of 2