Awplife develops a portfolio of WordPress plugins spanning galleries, sliders, blogs, and form builders that extend the platform's media and content functionality. The vendor's vulnerability exposure concentrates around web-application-layer weaknesses inherent to plugin development: cross-site scripting, missing authorization controls, cross-site request forgery, and in some instances insecure deserialization patterns that arise from handling user-supplied content and configuration data. The recurring products across disclosures—Event Monster, Album Gallery, Blog Filter, Formula, and Responsive Slideshow—reflect a modestly represented but durable signal in the WordPress ecosystem, where plugin updates often lag site maintenance cycles. Defenders should treat this vendor's advisories as applicable across WordPress installations using these plugins and prioritize patching in internet-exposed sites. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Awplife over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17072CRITICAL The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php. | Oct 10, 2019 | 9.8 | 29 | NO | NO |
CVE-2024-11396MEDIUM The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the | Jan 14, 2025 | 5.3 | 26 | NO | YES |
CVE-2024-35722HIGH Missing Authorization vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow.This issue affects Slider Responsive Slideshow – Image slider, Galler | Jun 10, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-35721HIGH Missing Authorization vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery.This issue affects Image Gallery – Lightbox Gallery, Re | Jun 10, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-1859HIGH The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8 via deseria | Mar 1, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-23646HIGH Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions. | Jul 17, 2023 | 8.8 | 25 | NO | NO |
CVE-2024-35720HIGH Missing Authorization vulnerability in A WP Life Album Gallery – WordPress Gallery.This issue affects Album Gallery – WordPress Gallery: from n/a through 1.5.7. | Jun 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-35717HIGH Missing Authorization vulnerability in A WP Life Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow.This issue affects Media Slider – Photo Sleder, Video Sl | Jun 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-3720HIGH The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by h | Nov 21, 2022 | 7.2 | 24 | NO | NO |
CVE-2024-1895HIGH The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.9 via des | Apr 30, 2024 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Awplife.
Media articles that mention a CVE ID that affects a product developed by Awplife — matched by CVE ID, not by vendor name.