Where
-Infinity
0

WpDevArt WpDevArt Organization chartWordPress Organization chart plugin <= 1.7.5 - Cross Site Request Forgery (CSRF) vulnerability

Risk 22
Severity
4.3
First published (updated )

WpDevArt Booking Calendar (Appointment Booking System)WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Cross Site Scripting (XSS) vulnerability

Risk 50
Severity
7.1
First published (updated )

WpDevArt Booking calendar, Appointment Booking SystemWordPress Booking calendar, Appointment Booking System plugin <= 3.2.30 - Broken Access Control vulnerability

Risk 27
Severity
5.3
First published (updated )

WpDevArt wpdevart-pricing-tableWordPress Pricing Table builder plugin <= 1.5.3 - Cross Site Request Forgery (CSRF) vulnerability

Risk 50
Severity
7.1
First published (updated )

WpDevArt Widget CountdownWordPress Widget Countdown plugin <= 2.7.4 - Cross Site Scripting (XSS) Vulnerability

Risk 34
Severity
6.5
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WpDevArt Widget CountdownWordPress Widget Countdown plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability

Risk 26
Severity
6.5
EPSS
0.04%
First published (updated )

WpDevArt Gallery WordpressWordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerability

Risk 34
Severity
5.4
First published (updated )

WpDevArt Booking CalendarBooking Calendar WpDevArt <= 3.2.19 - Authenticated (Contributor+) SQL Injection

Risk 38
Severity
6.5
First published (updated )

WpDevArt Booking calendar, Appointment Booking SystemWordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Broken Access Control vulnerability

Risk 79
Severity
8.8
First published (updated )

WordPress Organization ChartOrganization chart <= 1.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via title_input and node_description Parameters

Risk 25
Severity
5.4
EPSS
0.07%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WpDevArt Gallery WordpressWordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerability

Risk 46
Severity
6.3
First published (updated )

WpDevArt Gallery WordpressWordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - SQL Injection vulnerability

Risk 79
Severity
8.8
First published (updated )

WpDevArt Coming soon and Maintenance modeWordPress Coming soon and Maintenance mode plugin <= 3.7.3 - IP Filtering Bypass vulnerability

Risk 20
Severity
3.7
First published (updated )

WpDevArt Booking calendar, Appointment Booking SystemWordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability

Risk 86
Severity
9.8
First published (updated )

WpDevArt Responsive Image Gallery, Gallery AlbumWordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) vulnerability

Risk 36
Severity
7.1
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WpDevArt Responsive Image Gallery, Gallery AlbumWordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerability

Risk 34
Severity
6.5
EPSS
0.04%
First published (updated )

WpDevArt Countdown And Countup\, Woocommerce Sales Timer WordpressWordPress Countdown and CountUp, WooCommerce Sales Timer Plugin <= 1.8.2 is vulnerable to Cross Site Scripting (XSS)

Risk 40
Severity
5.9
First published (updated )

WpDevArt Booking Calendar WordpressWordPress Booking calendar, Appointment Booking System plugin <= 3.2.7 - SQL Injection

Risk 86
Severity
9.8
First published (updated )

WpDevArt Contact Form Builder WordpressWordPress Contact Form Builder, Contact Widget Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS)

Risk 50
Severity
7.1
First published (updated )

WpDevArt Gallery WordpressWordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)

Risk 50
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Total-Soft Portfolio Gallery Responsive Image Gallery WordpressWordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Request Forgery (CSRF)

Risk 77
Severity
8.8
First published (updated )

WpDevArt Pricing Table Builder WordpressAP Pricing Tables Lite <= 1.1.6 - Admin+ SQLi

Risk 66
Severity
7.2
First published (updated )

WpDevArt Organization Chart WordpressWordPress Organization chart Plugin <= 1.4.4 is vulnerable to Cross Site Scripting (XSS)

Risk 40
Severity
5.9
First published (updated )

WpDevArt Youtube Embed\, Playlist And Popup WordpressWordPress YouTube Embed, Playlist and Popup by WpDevArt Plugin <= 2.6.3 is vulnerable to Cross Site Scripting (XSS)

Risk 40
Severity
5.9
First published (updated )

WpDevArt Download Image And Video Lightbox\, Image Popup WordpressWordPress Image and Video Lightbox, Image PopUp Plugin <= 2.1.5 is vulnerable to Cross Site Scripting (XSS)

Risk 40
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WpDevArt Social Like Box And Page WordpressWordPress Social Like Box and Page by WpDevArt Plugin <= 0.8.39 is vulnerable to Cross Site Scripting (XSS)

Risk 40
Severity
5.9
First published (updated )

WpDevArt Responsive Vertical Icon Menu WordpressWordPress Responsive Vertical Icon Menu Plugin <= 1.5.8 is vulnerable to Cross Site Scripting (XSS)

Risk 40
Severity
5.9
First published (updated )

WpDevArt Image And Video Gallery With Thumbnails WordpressWordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS)

Risk 50
Severity
7.1
First published (updated )

WpDevArt Booking Calendar WordpressWordPress Booking calendar, Appointment Booking System Plugin <= 3.2.3 is vulnerable to Cross Site Scripting (XSS)

Risk 40
Severity
5.9
First published (updated )

WpDevArt Responsive Vertical Icon Menu WordpressWordPress Responsive Vertical Icon Menu Plugin <= 1.5.8 is vulnerable to Cross Site Request Forgery (CSRF)

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203