Wpdevart develops a suite of WordPress plugins spanning calendars, galleries, charts, countdowns, and e-commerce integrations that are widely deployed across small-to-medium business websites. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the web-facing nature and accessibility of WordPress plugin ecosystems. The exposure recurs across the plugin portfolio through classic application-layer weakness classes including cross-site scripting, SQL injection, cross-site request forgery, missing authorization, and improper handling of web parameters, which are endemic to server-side web applications that accept and process user input. Defenders should prioritize updates for these widely installed plugins and implement input validation, output encoding, and CSRF protections at both the plugin and WordPress configuration levels. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpdevart over time
Signals from CVEs in this vendor scope (43 CVEs).
43 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24442CRITICAL The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL stat | Jul 12, 2021 | 9.8 | 67 | NO | YES |
CVE-2022-3982CRITICAL The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, | Dec 12, 2022 | 9.8 | 43 | NO | YES |
CVE-2023-0900HIGH The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitabl | Jun 5, 2023 | 7.2 | 32 | NO | YES |
CVE-2017-14125CRITICAL SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an | Sep 25, 2017 | 9.8 | 30 | NO | NO |
CVE-2025-62886HIGH Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Pricing Table builder wpdevart-pricing-table allows Stored XSS.This issue affects Pricing Table builder: from n/a throug | Oct 27, 2025 | 8.8 | 28 | NO | NO |
CVE-2023-24384HIGH Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions. | Feb 23, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-34636HIGH The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_ | Sep 28, 2021 | 8.8 | 27 | NO | NO |
CVE-2024-35750HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevart Responsive Image Gallery, Gallery Album.This issue affects Responsive | Jun 8, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-24373CRITICAL External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Book | Jun 3, 2024 | 9.8 | 26 | NO | NO |
CVE-2022-47428CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.Thi | Nov 6, 2023 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (43 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpdevart.
Media articles that mention a CVE ID that affects a product developed by Wpdevart — matched by CVE ID, not by vendor name.