Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Awplife

First CVE: Oct 10, 2019Active for: 7 yearsTotal CVEs: 28
31.7
VTI Score
Medium

Awplife develops a portfolio of WordPress plugins spanning galleries, sliders, blogs, and form builders that extend the platform's media and content functionality. The vendor's vulnerability exposure concentrates around web-application-layer weaknesses inherent to plugin development: cross-site scripting, missing authorization controls, cross-site request forgery, and in some instances insecure deserialization patterns that arise from handling user-supplied content and configuration data. The recurring products across disclosures—Event Monster, Album Gallery, Blog Filter, Formula, and Responsive Slideshow—reflect a modestly represented but durable signal in the WordPress ecosystem, where plugin updates often lag site maintenance cycles. Defenders should treat this vendor's advisories as applicable across WordPress installations using these plugins and prioritize patching in internet-exposed sites. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Awplife over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2019
6 years ago
Most Recent CVE
Apr 8, 2026
107 days ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-17072CRITICAL
The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.
Oct 10, 20199.829NONO
CVE-2024-11396MEDIUM
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the
Jan 14, 20255.326NOYES
CVE-2024-35722HIGH
Missing Authorization vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow.This issue affects Slider Responsive Slideshow – Image slider, Galler
Jun 10, 20248.825NONO
CVE-2024-35721HIGH
Missing Authorization vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery.This issue affects Image Gallery – Lightbox Gallery, Re
Jun 10, 20248.825NONO
CVE-2024-1859HIGH
The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8 via deseria
Mar 1, 20248.825NONO
CVE-2023-23646HIGH
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.
Jul 17, 20238.825NONO
CVE-2024-35720HIGH
Missing Authorization vulnerability in A WP Life Album Gallery – WordPress Gallery.This issue affects Album Gallery – WordPress Gallery: from n/a through 1.5.7.
Jun 10, 20248.824NONO
CVE-2024-35717HIGH
Missing Authorization vulnerability in A WP Life Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow.This issue affects Media Slider – Photo Sleder, Video Sl
Jun 10, 20248.824NONO
CVE-2022-3720HIGH
The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by h
Nov 21, 20227.224NONO
CVE-2024-1895HIGH
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.9 via des
Apr 30, 20247.523NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
61%
36%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (96.4%)
High1 (3.6%)
Unknown0 (0.0%)
User Interaction
None12 (42.9%)
Unknown0 (0.0%)
Required16 (57.1%)
Privileges Required
Low12 (42.9%)
High3 (10.7%)
None13 (46.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.6% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Awplife.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Awplife — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Awplife's Products

View all 4 CNAs →

Top CWEs