Wpsymposium develops a WordPress symposium plugin that serves event and conference management functions within WordPress deployments, with its vulnerability exposure centered on a single focused product. The observed weakness classes reflect input-handling limitations in the plugin's architecture, notably SQL injection conditions that are characteristic of web-application components lacking robust parameterization. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpsymposium over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-6522HIGH SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the size parameter to get_album_item. | Aug 19, 2015 | 7.5 | 76 | NO | YES |
CVE-2015-3325HIGH SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the show parameter in th | May 15, 2015 | 7.5 | 30 | NO | YES |
CVE-2011-5051HIGH Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file with | Jan 4, 2012 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpsymposium.
Media articles that mention a CVE ID that affects a product developed by Wpsymposium — matched by CVE ID, not by vendor name.