Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Web Dorado

First CVE: May 10, 2013Active for: 13 yearsTotal CVEs: 28

Web Dorado is a developer of WordPress plugins focused on content presentation and user engagement, including video players, contact forms, event calendars, and form-building tools that see wide adoption across WordPress-powered sites. The vendor's vulnerability disclosures span a modest product portfolio, primarily affecting plugins that interface directly with user input and site administration. While specific weakness classes have not consistently emerged as a durable pattern, the exposure reflects the parser, validation, and access-control surface typical of extensible WordPress components. Defenders should maintain awareness of this vendor's releases for widely deployed plugins and apply updates to both public-facing and administrative functionality; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Web Dorado over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 10, 2013
13 years ago
Most Recent CVE
Jan 16, 2024
923 days ago

Products(18 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-2562HIGH
Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute arbitrary SQL commands via the
Mar 20, 20157.558NOYES
CVE-2018-5991CRITICAL
SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798.
Feb 17, 20189.841NOYES
CVE-2015-2798CRITICAL
SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Jul 25, 20179.841NOYES
CVE-2015-2196HIGH
SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_m
Mar 3, 20157.541NOYES
CVE-2018-5981CRITICAL
SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.
Feb 17, 20189.839NOYES
CVE-2017-7719CRITICAL
SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or wi
Apr 12, 20179.832NONO
CVE-2018-10504HIGH
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
Apr 27, 20187.830NOYES
CVE-2013-3532HIGH
SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme p
May 10, 20137.530NOYES
CVE-2019-11557HIGH
The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via director
Apr 26, 20198.828NONO
CVE-2019-11591HIGH
The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traver
Apr 29, 20198.827NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
54%
32%
14%
Severity distribution among all CVEs352,727 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (3.6%)
Network19 (67.9%)
Unknown8 (28.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (71.4%)
High0 (0.0%)
Unknown8 (28.6%)
User Interaction
None7 (25.0%)
Unknown8 (28.6%)
Required13 (46.4%)
Privileges Required
Low3 (10.7%)
High4 (14.3%)
None13 (46.4%)
Unknown8 (28.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.6% of CVEs· 98th percentile
Nuclei
1 CVE
3.6% of CVEs· 95th percentile
ExploitDB
7 CVEs
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Web Dorado.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Web Dorado — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Web Dorado's Products

View all 5 CNAs →

Top CWEs