Devnath Verma's vulnerability footprint is centered on WordPress-related plugins, specifically the Widget Bundle and WP Captcha components, where the recurring exposure involves web-application input handling. The durable signal reflects cross-site request forgery and cross-site scripting weaknesses characteristic of plugin-layer access and form validation, rather than a vendor portfolio trend; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Devnath Verma over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44236HIGH Cross-Site Request Forgery (CSRF) vulnerability in Devnath verma WP Captcha plugin <= 2.0.0 versions. | Oct 9, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-4616MEDIUM The Widget Bundle WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which c | Jun 21, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-44235MEDIUM Improper Restriction of Excessive Authentication Attempts vulnerability in Devnath verma WP Captcha allows Functionality Bypass.This issue affects WP Captcha: from n/a through 2.0. | Jun 4, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-4970MEDIUM The Widget Bundle WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Sit | Jun 21, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-4969MEDIUM The Widget Bundle WordPress plugin through 2.0.0 does not have CSRF checks when logging Widgets, which could allow attackers to make logged in admin enable/disable widgets via a CS | Jun 21, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Devnath Verma.
Media articles that mention a CVE ID that affects a product developed by Devnath Verma — matched by CVE ID, not by vendor name.