CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Wpdevart Remove filter Clear all
CVE-2026-73395 MEDIUM

WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Insecure Direct Object References (IDOR) vulnerability

CVSS 6.5 EPSS 0.33% Aug 18, 2026
CVE-2026-8840 MEDIUM

Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action

CVSS 5.3 EPSS 0.55% Aug 15, 2026
CVE-2026-57778 MEDIUM

WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Broken Access Control vulnerability

CVSS 5.3 EPSS 0.29% Jul 13, 2026
CVE-2026-15289 MEDIUM

Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time-Based SQL Injection via 'wpdevart_id'

CVSS 5.9 EPSS 0.44% Jul 10, 2026
CVE-2026-24597 MEDIUM

WordPress Organization chart plugin <= 1.7.5 - Cross Site Request Forgery (CSRF) vulnerability

CVSS 4.3 EPSS 0.12% May 25, 2026
CVE-2022-50959 MEDIUM

WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php

CVSS 5.1 EPSS 0.21% May 10, 2026
CVE-2026-25435 HIGH

WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Cross Site Scripting (XSS) vulnerability

CVSS 7.1 EPSS 0.25% Mar 25, 2026
CVE-2025-14555 MEDIUM

Countdown Timer - Widget Countdown <= 2.7.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

CVSS 6.4 EPSS 0.22% Jan 10, 2026
CVE-2025-67574 MEDIUM

WordPress Booking calendar, Appointment Booking System plugin <= 3.2.30 - Broken Access Control vulnerability

CVSS 5.3 EPSS 0.25% Dec 9, 2025
CVE-2025-62886 HIGH

WordPress Pricing Table builder plugin <= 1.5.3 - Cross Site Request Forgery (CSRF) vulnerability

CVSS 7.1 EPSS 0.14% Oct 27, 2025
CVE-2025-2537 MEDIUM

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library

CVSS 6.4 EPSS 0.29% Jul 3, 2025
CVE-2025-47443 MEDIUM

WordPress Widget Countdown plugin <= 2.7.4 - Cross Site Scripting (XSS) Vulnerability

CVSS 6.5 EPSS 0.27% May 7, 2025
CVE-2025-24719 MEDIUM

WordPress Widget Countdown plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability

CVSS 6.5 EPSS 0.30% Jan 24, 2025
CVE-2024-12077 MEDIUM

Booking Calendar and Booking Calendar Pro <= Multiple Versions - Reflected Cross-Site Scripting via 'calendar_id'

CVSS 6.1 EPSS 0.37% Jan 7, 2025
CVE-2023-45631 MEDIUM

WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerability

CVSS 5.4 EPSS 0.31% Jan 2, 2025
CVE-2024-10856 MEDIUM

Booking Calendar WpDevArt <= 3.2.19 - Authenticated (Contributor+) SQL Injection

CVSS 6.5 EPSS 0.49% Dec 24, 2024
CVE-2023-24407 HIGH

WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Broken Access Control vulnerability

CVSS 8.8 EPSS 0.50% Dec 9, 2024
CVE-2024-9504 HIGH

Booking calendar, Appointment Booking System <= 3.2.15 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload

CVSS 7.2 EPSS 0.47% Nov 26, 2024
CVE-2024-7355 MEDIUM

Organization chart <= 1.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via title_input and node_description Parameters

CVSS 5.4 EPSS 0.33% Aug 7, 2024
CVE-2024-37542 MEDIUM

WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerability

CVSS 6.3 EPSS 0.25% Jul 6, 2024
CVE-2024-35747 MEDIUM

WordPress Contact Form Builder, Contact Widget plugin <= 2.1.7 - Bypass Vulnerability vulnerability

CVSS 5.3 EPSS 0.37% Jun 10, 2024
CVE-2024-35750 HIGH

WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - SQL Injection vulnerability

CVSS 8.8 EPSS 0.44% Jun 8, 2024
CVE-2023-49741 LOW

WordPress Coming soon and Maintenance mode plugin <= 3.7.3 - IP Filtering Bypass vulnerability

CVSS 3.7 EPSS 0.34% Jun 4, 2024
CVE-2023-24373 CRITICAL

WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability

CVSS 9.8 EPSS 0.35% Jun 3, 2024
CVE-2024-30550 HIGH

WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) vulnerability

CVSS 7.1 EPSS 0.40% Mar 31, 2024

Showing 1 to 25 CVEs · page 1 (more available)