Wpdevart
12 CVEs tracked since 2022. Since Feb 2022, none of them reached CISA KEV.
Wpdevart CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-02 | 3 | 0 |
| 2022-03 | null or fewer | |
| 2022-04 | null or fewer | |
| 2022-05 | null or fewer | |
| 2022-06 | null or fewer | |
| 2022-07 | null or fewer | |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | null or fewer | |
| 2022-11 | null or fewer | |
| 2022-12 | null or fewer | |
| 2023-01 | null or fewer | |
| 2023-02 | 4 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 5 | 0 |
Products
The products that kept showing up in Wpdevart's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Wpdevart.
- CVE-2026-73395WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Insecure Direct Object References (IDOR) vulnerability6.5
- CVE-2026-8840Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action5.3
- CVE-2026-57778WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Broken Access Control vulnerability5.3
- CVE-2026-15289Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time-Based SQL Injection via 'wpdevart_id'5.9
- CVE-2026-24597WordPress Organization chart plugin <= 1.7.5 - Cross Site Request Forgery (CSRF) vulnerability4.3
- CVE-2022-50959WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php6.1
- CVE-2026-25435WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2025-14555Countdown Timer - Widget Countdown <= 2.7.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode6.4
- CVE-2025-67574WordPress Booking calendar, Appointment Booking System plugin <= 3.2.30 - Broken Access Control vulnerability5.3
- CVE-2025-62886WordPress Pricing Table builder plugin <= 1.5.3 - Cross Site Request Forgery (CSRF) vulnerability7.1
- CVE-2025-2537Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library6.4
- CVE-2025-47443WordPress Widget Countdown plugin <= 2.7.4 - Cross Site Scripting (XSS) Vulnerability6.5
- CVE-2025-24719WordPress Widget Countdown plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2024-12077Booking Calendar and Booking Calendar Pro <= Multiple Versions - Reflected Cross-Site Scripting via 'calendar_id'6.1
- CVE-2023-45631WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerability4.3
The record
- Peak rank
- #152 in Apr 2023
- Busiest month shown
- Apr 2023, 5 CVEs
- Months with a KEV entry
- 0 since Feb 2022
- Monthly snapshots
- 3 since 2022