Web Dorado is a developer of WordPress plugins focused on content presentation and user engagement, including video players, contact forms, event calendars, and form-building tools that see wide adoption across WordPress-powered sites. The vendor's vulnerability disclosures span a modest product portfolio, primarily affecting plugins that interface directly with user input and site administration. While specific weakness classes have not consistently emerged as a durable pattern, the exposure reflects the parser, validation, and access-control surface typical of extensible WordPress components. Defenders should maintain awareness of this vendor's releases for widely deployed plugins and apply updates to both public-facing and administrative functionality; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Web Dorado over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2562HIGH Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute arbitrary SQL commands via the | Mar 20, 2015 | 7.5 | 58 | NO | YES |
CVE-2018-5991CRITICAL SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798. | Feb 17, 2018 | 9.8 | 41 | NO | YES |
CVE-2015-2798CRITICAL SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jul 25, 2017 | 9.8 | 41 | NO | YES |
CVE-2015-2196HIGH SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_m | Mar 3, 2015 | 7.5 | 41 | NO | YES |
CVE-2018-5981CRITICAL SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter. | Feb 17, 2018 | 9.8 | 39 | NO | YES |
CVE-2017-7719CRITICAL SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or wi | Apr 12, 2017 | 9.8 | 32 | NO | NO |
CVE-2018-10504HIGH The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. | Apr 27, 2018 | 7.8 | 30 | NO | YES |
CVE-2013-3532HIGH SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme p | May 10, 2013 | 7.5 | 30 | NO | YES |
CVE-2019-11557HIGH The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via director | Apr 26, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-11591HIGH The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traver | Apr 29, 2019 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Web Dorado.
Media articles that mention a CVE ID that affects a product developed by Web Dorado — matched by CVE ID, not by vendor name.