CVE Tools

Wpdevart

12 CVEs tracked since 2022. Since Feb 2022, none of them reached CISA KEV.

Wpdevart CVEs per month

Feb 2022 to Apr 2023. Point at a month, or focus the strip and use the arrow keys.
Wpdevart CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-0230
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-0240
2023-03null or fewer
2023-0450

Products

The products that kept showing up in Wpdevart's monthly top three, with their CVEs summed over those months.

  1. Coming Soon and Maintenance Mode21 month
  2. Organization Chart22 months
  3. Booking Calendar11 month
  4. Booking Calendar, Appointment Booking System11 month
  5. Download Image and Video Lightbox\, Image Popup11 month
  6. Duplicate Page Or Post11 month
  7. Image and Video Lightbox, Image Popup11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Wpdevart.

  1. CVE-2026-73395WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Insecure Direct Object References (IDOR) vulnerability6.5
  2. CVE-2026-8840Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action5.3
  3. CVE-2026-57778WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Broken Access Control vulnerability5.3
  4. CVE-2026-15289Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time-Based SQL Injection via 'wpdevart_id'5.9
  5. CVE-2026-24597WordPress Organization chart plugin <= 1.7.5 - Cross Site Request Forgery (CSRF) vulnerability4.3
  6. CVE-2022-50959WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php6.1
  7. CVE-2026-25435WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Cross Site Scripting (XSS) vulnerability7.1
  8. CVE-2025-14555Countdown Timer - Widget Countdown <= 2.7.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode6.4
  9. CVE-2025-67574WordPress Booking calendar, Appointment Booking System plugin <= 3.2.30 - Broken Access Control vulnerability5.3
  10. CVE-2025-62886WordPress Pricing Table builder plugin <= 1.5.3 - Cross Site Request Forgery (CSRF) vulnerability7.1
  11. CVE-2025-2537Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library6.4
  12. CVE-2025-47443WordPress Widget Countdown plugin <= 2.7.4 - Cross Site Scripting (XSS) Vulnerability6.5
  13. CVE-2025-24719WordPress Widget Countdown plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability6.5
  14. CVE-2024-12077Booking Calendar and Booking Calendar Pro <= Multiple Versions - Reflected Cross-Site Scripting via 'calendar_id'6.1
  15. CVE-2023-45631WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerability4.3

The record

Peak rank
#152 in Apr 2023
Busiest month shown
Apr 2023, 5 CVEs
Months with a KEV entry
0 since Feb 2022
Monthly snapshots
3 since 2022
Wpdevart's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store