Webdorado develops a focused line of WordPress plugins and web components, including video players, contact forms, event calendars, and form builders. The durable signal across its disclosures centers on SQL injection vulnerabilities, reflecting input-handling risks common to database-backed web applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webdorado over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2562HIGH Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute arbitrary SQL commands via the | Mar 20, 2015 | 7.5 | 58 | NO | YES |
CVE-2018-5991CRITICAL SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798. | Feb 17, 2018 | 9.8 | 41 | NO | YES |
CVE-2015-2798CRITICAL SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jul 25, 2017 | 9.8 | 41 | NO | YES |
CVE-2015-2196HIGH SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_m | Mar 3, 2015 | 7.5 | 41 | NO | YES |
CVE-2018-5981CRITICAL SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter. | Feb 17, 2018 | 9.8 | 39 | NO | YES |
CVE-2017-7719CRITICAL SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or wi | Apr 12, 2017 | 9.8 | 32 | NO | NO |
CVE-2018-10504HIGH The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. | Apr 27, 2018 | 7.8 | 30 | NO | YES |
CVE-2013-3532HIGH SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme p | May 10, 2013 | 7.5 | 30 | NO | YES |
CVE-2019-11557HIGH The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via director | Apr 26, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-11591HIGH The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traver | Apr 29, 2019 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webdorado.
Media articles that mention a CVE ID that affects a product developed by Webdorado — matched by CVE ID, not by vendor name.