Devfarm's vulnerability profile centers on its WordPress GPX Maps plugin, a modest but specialized component for mapping functionality in WordPress environments, with disclosed weaknesses clustering around web application input handling and access control. The recurring weakness classes—cross-site scripting, missing authorization, and unrestricted file uploads—are characteristic of plugin-layer logic where input validation and permission enforcement boundaries are frequently overlooked. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Devfarm over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6649CRITICAL WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload. | Jan 23, 2020 | 9.8 | 51 | NO | YES |
CVE-2024-9028MEDIUM The WP GPX Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sgpx' shortcode in all versions up to, and including, 1.7.08 due to insufficient | Sep 25, 2024 | 5.4 | 16 | NO | NO |
CVE-2023-44234MEDIUM Missing Authorization vulnerability in Bastianon Massimo WP GPX Map.This issue affects WP GPX Map: from n/a through 1.7.08. | Jun 12, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Devfarm.
Media articles that mention a CVE ID that affects a product developed by Devfarm — matched by CVE ID, not by vendor name.