Smartdatasoft develops a focused set of WordPress-oriented plugins and services spanning real estate, classified listings, automotive, and blogging functionality, each representing a potential point of exposure across numerous WordPress installations. Vulnerabilities affecting this vendor concentrate in web application input-handling issues—principally cross-site scripting and SQL injection—paired with data-structure integrity flaws, and the portfolio skews toward serious outcomes with a notable tendency toward public exploit availability. Defenders deploying these plugins should prioritize input-validation and parameterized-query practices and monitor for updates; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smartdatasoft over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-37538CRITICAL Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, | Aug 24, 2021 | 9.8 | 81 | NO | YES |
CVE-2021-24335MEDIUM The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading | Jun 1, 2021 | 6.1 | 32 | NO | YES |
CVE-2020-36972HIGH SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database information. Attackers c | Jan 28, 2026 | 7.5 | 24 | NO | NO |
CVE-2024-12725MEDIUM The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scri | May 15, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-23857MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SmartDataSoft Essential WP Real Estate essential-wp-real-estate allows Reflect | Feb 14, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-13347MEDIUM The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting. | Feb 3, 2025 | 6.8 | 18 | NO | NO |
CVE-2024-13318MEDIUM The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up | Jan 10, 2025 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smartdatasoft.
Media articles that mention a CVE ID that affects a product developed by Smartdatasoft — matched by CVE ID, not by vendor name.