Wpdarko develops a focused suite of WordPress plugins including Team Members, Responsive Pricing Table, Responsive Tabs, Top Bar, and Grid Shortcodes that extend content presentation and layout capabilities for website administrators. The vendor's vulnerability profile centers on cross-site scripting weaknesses arising from improper input neutralization in web page generation, a common exposure class for plugin-based extensions to WordPress that handle user-supplied content or configuration. Current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpdarko over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4096MEDIUM The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to p | Jul 30, 2024 | 5.9 | 20 | NO | NO |
CVE-2022-46855MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP Darko Responsive Pricing Table plugin <= 5.1.6 versions. | Mar 28, 2023 | 5.4 | 20 | NO | NO |
CVE-2024-38670MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Members allows Stored XSS.This issue affects Team Members: from n/ | Jul 20, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-1331MEDIUM The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed | Mar 18, 2024 | 6.1 | 19 | NO | NO |
CVE-2022-3936MEDIUM The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow high-privilege users such as editors to perform Stored Cross-Si | Jan 2, 2023 | 4.8 | 19 | NO | NO |
CVE-2022-2629MEDIUM The Top Bar WordPress plugin before 3.0.4 does not sanitise and escape some of its settings before outputting them in frontend pages, which could allow high privilege users such as | Oct 10, 2022 | 4.8 | 19 | NO | NO |
CVE-2021-24128MEDIUM Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged a | Mar 18, 2021 | 5.4 | 19 | NO | NO |
CVE-2023-45635MEDIUM Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs allows Code Injection.This issue affects Responsive Tabs: fr | Jun 4, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-1846MEDIUM The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is em | Apr 15, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-31928MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Darko Top Bar allows Stored XSS.This issue affects Top Bar: from n/a throug | Apr 11, 2024 | 5.9 | 18 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpdarko.
Media articles that mention a CVE ID that affects a product developed by Wpdarko — matched by CVE ID, not by vendor name.