Bhzad's vulnerability exposure centers on a WordPress plugin, the jQuery Persian Datepicker, which provides localized calendar functionality for Persian-language websites. The identified vulnerability pattern reflects a cross-site request forgery weakness characteristic of plugin-based web extensions that handle user input without sufficient request validation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bhzad over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-28861MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in bhzad WP jQuery Persian Datepicker wpjqp-datepicker allows Stored XSS.This issue affects WP jQuery Persian Datepicker: from n/a t | Mar 11, 2025 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bhzad.
Media articles that mention a CVE ID that affects a product developed by Bhzad — matched by CVE ID, not by vendor name.