Dev4press produces a narrowly focused line of WordPress-ecosystem plugins including community-engagement and content-rating tools such as GD bbPress Attachments, CoreActivity, and GD Rating System. The vendor's durable weakness profile centers on application-layer input-handling issues endemic to web plugins: cross-site scripting, SQL injection, cross-site request forgery, and path traversal, reflecting the challenges of secure form processing and URL handling in WordPress extensions. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dev4press over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42639CRITICAL Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions. | Jun 15, 2026 | 9.3 | 30 | NO | NO |
CVE-2024-0852HIGH The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated user | May 15, 2025 | 8.8 | 23 | NO | NO |
CVE-2023-46821HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Security Headers allows auth. (admin+) SQL Injection.This is | Nov 6, 2023 | 7.2 | 21 | NO | NO |
CVE-2017-18591MEDIUM The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php. | Aug 27, 2019 | 6.1 | 21 | NO | NO |
CVE-2023-3122MEDIUM The GD Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 3.9.3 due to insufficient input sanitizatio | Jul 12, 2023 | 6.1 | 19 | NO | NO |
CVE-2022-45816MEDIUM Auth. Stored Cross-Site Scripting (XSS) vulnerability in GD bbPress Attachments plugin <= 4.3.1 on WordPress. | Dec 6, 2022 | 5.4 | 19 | NO | NO |
CVE-2014-2839HIGH SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands via the s parameter in the gd-star-ratin | Jan 12, 2015 | 7.5 | 19 | NO | NO |
CVE-2024-25093MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Rating System allows Stored XSS.This issue affects GD Rating | Feb 29, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-40330MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Milan Petrovic GD Security Headers plugin <= 1.6.1 versions. | Sep 27, 2023 | 6.1 | 18 | NO | NO |
CVE-2014-2838MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 19.22 for WordPress allow remote attackers to hijack the authentication of administrators fo | Jan 12, 2015 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dev4press.
Media articles that mention a CVE ID that affects a product developed by Dev4press — matched by CVE ID, not by vendor name.