Androidbubbles maintains a narrow portfolio of WordPress plugins including WP Datepicker, Endless Posts Navigation, Keep Backup Daily, and WP Header Images that serve a focused audience in the WordPress ecosystem. The vendor's vulnerabilities skew toward serious outcomes and recur through web-application layer weakness classes—cross-site scripting, missing authorization checks, and cross-site request forgery—that are typical of plugin development where input handling and access control are critical. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Androidbubbles over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-47321CRITICAL Missing Authorization vulnerability in Fahad Mahmood WP Datepicker wp-datepicker.This issue affects WP Datepicker: from n/a through <= 2.1.1. | Nov 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-3895HIGH The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpdp_add_new_datepicker_ajax() function in all ve | May 2, 2024 | 8.8 | 25 | NO | NO |
CVE-2022-1820MEDIUM The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘t’ parameter in versions up to, and including, 2.0.2 due to insufficient input s | Jun 13, 2022 | 6.1 | 21 | NO | NO |
CVE-2021-24798MEDIUM The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it back in the plugin's settings page, leading to a Reflected Cros | Nov 8, 2021 | 6.1 | 21 | NO | NO |
CVE-2024-12468MEDIUM The WP Datepicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpdp_get_selected_datepicker' parameter in all versions up to, and including, 2.1.4 | Dec 24, 2024 | 6.1 | 20 | NO | NO |
CVE-2024-49629MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Fahad Mahmood Endless Posts Navigation endless-posts-navigation allows Stored XSS.This issue affects Endless Posts Navigation: fr | Oct 20, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-44042MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Datepicker wp-datepicker allows Stored XSS.This issue affects | Oct 6, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Androidbubbles.
Media articles that mention a CVE ID that affects a product developed by Androidbubbles — matched by CVE ID, not by vendor name.