Dwbooster develops a modestly represented suite of WordPress plugins for appointment booking, event calendars, form builders, and advertising management that serve web publishers and small businesses. Its vulnerability profile centers consistently on web-application input-handling and session-management weaknesses—cross-site scripting, cross-site request forgery, missing authorization checks, and weak CAPTCHA implementations—that are characteristic of PHP-based plugin development; these classes frequently acquire public exploit code. Defenders managing WordPress deployments should monitor this vendor's updates and audit plugin permissions and user-input contexts; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dwbooster over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1692CRITICAL The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the | Jun 8, 2022 | 9.8 | 48 | NO | YES |
CVE-2021-24498MEDIUM The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), | Aug 2, 2021 | 6.1 | 31 | NO | YES |
CVE-2022-41692HIGH Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress. | Nov 18, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-2846MEDIUM The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as we | Aug 16, 2022 | 4.3 | 27 | NO | YES |
CVE-2022-4034HIGH The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to e | Nov 29, 2022 | 7.8 | 26 | NO | NO |
CVE-2023-41732HIGH Cross-Site Request Forgery (CSRF) vulnerability in CodePeople CP Blocks plugin <= 1.0.20 versions. | Oct 6, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-0448MEDIUM The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks | Mar 7, 2022 | 4.8 | 24 | NO | YES |
CVE-2022-3427MEDIUM The Corner Ad plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.56. This is due to missing or incorrect nonce validation on its | Dec 15, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-4035MEDIUM The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field parameters in versions up to, and including, 1.3.72 due to insu | Nov 29, 2022 | 6.1 | 22 | NO | NO |
CVE-2024-13758MEDIUM The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This is due to missing or incorrect n | Jan 30, 2025 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dwbooster.
Media articles that mention a CVE ID that affects a product developed by Dwbooster — matched by CVE ID, not by vendor name.