Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpdevart

First CVE: Sep 25, 2017Active for: 9 yearsTotal CVEs: 43
30.7
VTI Score
Low

Wpdevart develops a suite of WordPress plugins spanning calendars, galleries, charts, countdowns, and e-commerce integrations that are widely deployed across small-to-medium business websites. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the web-facing nature and accessibility of WordPress plugin ecosystems. The exposure recurs across the plugin portfolio through classic application-layer weakness classes including cross-site scripting, SQL injection, cross-site request forgery, missing authorization, and improper handling of web parameters, which are endemic to server-side web applications that accept and process user input. Defenders should prioritize updates for these widely installed plugins and implement input validation, output encoding, and CSRF protections at both the plugin and WordPress configuration levels. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
43
Total CVEs
More Total CVEs than 98% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpdevart over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 25, 2017
8 years ago
Most Recent CVE
May 25, 2026
62 days ago

Products(17 total)

Top CVEs

Signals from CVEs in this vendor scope (43 CVEs).

43 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24442CRITICAL
The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL stat
Jul 12, 20219.867NOYES
CVE-2022-3982CRITICAL
The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files,
Dec 12, 20229.843NOYES
CVE-2023-0900HIGH
The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitabl
Jun 5, 20237.232NOYES
CVE-2017-14125CRITICAL
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an
Sep 25, 20179.830NONO
CVE-2025-62886HIGH
Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Pricing Table builder wpdevart-pricing-table allows Stored XSS.This issue affects Pricing Table builder: from n/a throug
Oct 27, 20258.828NONO
CVE-2023-24384HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions.
Feb 23, 20238.827NONO
CVE-2021-34636HIGH
The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_
Sep 28, 20218.827NONO
CVE-2024-35750HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevart Responsive Image Gallery, Gallery Album.This issue affects Responsive
Jun 8, 20248.826NONO
CVE-2023-24373CRITICAL
External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Book
Jun 3, 20249.826NONO
CVE-2022-47428CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.Thi
Nov 6, 20239.826NONO
View all 43 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products43 CVEs
65%
19%
12%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network43 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low42 (97.7%)
High1 (2.3%)
Unknown0 (0.0%)
User Interaction
None14 (32.6%)
Unknown0 (0.0%)
Required29 (67.4%)
Privileges Required
Low13 (30.2%)
High9 (20.9%)
None21 (48.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (43 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
11.6% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpdevart.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpdevart — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpdevart's Products

View all 4 CNAs →

Top CWEs