Wpopal develops a focused suite of WordPress-based property management and hospitality booking solutions including Opal Estate and Opal Hotel Room Booking, with its vulnerability profile centered on web-application input handling and authorization flaws. The recurring weakness classes—cross-site request forgery, cross-site scripting, missing authorization, and server-side request forgery—reflect the interaction-heavy nature of booking and administrative interfaces exposed to untrusted user input. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpopal over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40700CRITICAL Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch S | Jan 19, 2024 | 9.8 | 29 | NO | NO |
CVE-2021-4387HIGH The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11. This is due to missing or incorrect nonce validation on t | Jul 1, 2023 | 8.8 | 24 | NO | NO |
CVE-2021-4388MEDIUM The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11. This is due to missing capability checks on the opa | Jul 1, 2023 | 5.3 | 17 | NO | NO |
CVE-2022-29449MEDIUM Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Opal Hotel Room Booking plugin <= 1.2.7 at WordPress. | May 19, 2022 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpopal.
Media articles that mention a CVE ID that affects a product developed by Wpopal — matched by CVE ID, not by vendor name.