Bestwebsoft develops a modestly represented portfolio of WordPress plugins and web application extensions, spanning contact-form builders, database connectors, analytics tools, and media galleries that serve small-to-medium web administrators. The vendor's vulnerability profile centers on application-layer input-handling weaknesses characteristic of plugin development: cross-site scripting, SQL injection, and cross-site request forgery recur across its product line, and public exploit code frequently becomes available for these classes. While the severity distribution is moderate, the high tendency toward public exploit availability reflects the appeal of WordPress plugin vulnerabilities to both security researchers and adversaries targeting website infrastructure. Defenders should treat Bestwebsoft plugin updates as part of routine WordPress hardening and monitor for indicators of attack against unpatched instances; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bestwebsoft over time
Signals from CVEs in this vendor scope (77 CVEs).
77 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57642HIGH Contributor SQL Injection in Gallery <= 4.7.8 versions. | Jun 26, 2026 | 8.5 | 35 | NO | NO |
CVE-2022-3393CRITICAL The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection | Oct 25, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-24966MEDIUM The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, i | Mar 14, 2022 | 4.9 | 30 | NO | YES |
CVE-2020-8658HIGH The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to | Feb 6, 2020 | 8.8 | 30 | NO | NO |
CVE-2017-18590MEDIUM The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues. | Aug 27, 2019 | 6.1 | 30 | NO | YES |
CVE-2017-18565MEDIUM The updater plugin before 1.35 for WordPress has multiple XSS issues. | Aug 21, 2019 | 6.1 | 30 | NO | YES |
CVE-2015-9325CRITICAL The visitors-online plugin before 0.4 for WordPress has SQL injection. | Aug 16, 2019 | 9.8 | 30 | NO | NO |
CVE-2017-18564MEDIUM The sender plugin before 1.2.1 for WordPress has multiple XSS issues. | Aug 21, 2019 | 6.1 | 29 | NO | YES |
CVE-2017-18558MEDIUM The bws-testimonials plugin before 0.1.9 for WordPress has multiple XSS issues. | Aug 21, 2019 | 6.1 | 29 | NO | YES |
CVE-2017-18557MEDIUM The bws-google-maps plugin before 1.3.6 for WordPress has multiple XSS issues. | Aug 21, 2019 | 6.1 | 29 | NO | YES |
Signals from CVEs in this vendor scope (77 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bestwebsoft.
Media articles that mention a CVE ID that affects a product developed by Bestwebsoft — matched by CVE ID, not by vendor name.