WP Symposium Pro is a WordPress plugin that focuses on community and event management functionality, presenting a modestly represented vulnerability footprint concentrated in a single product. The recurring exposure centers on web-application input-handling weaknesses, including cross-site scripting, SQL injection, and improper input validation, which are characteristic of PHP-based plugins operating within the WordPress ecosystem. Public exploit code has frequently accompanied disclosures for this vendor, making timely patching essential for deployments; live severity, KEV status, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpsymposiumpro over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-10021HIGH Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote attackers to execute arbitrary code by uploading a file wit | Jan 13, 2015 | 7.5 | 69 | NO | YES |
CVE-2014-8810MEDIUM SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via | Dec 24, 2014 | 6.5 | 27 | NO | YES |
CVE-2015-9414MEDIUM The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter. | Sep 26, 2019 | 6.1 | 26 | NO | YES |
CVE-2013-2694MEDIUM Open redirect vulnerability in invite.php in the WP Symposium plugin 13.04 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attac | Mar 28, 2014 | 5.8 | 21 | NO | NO |
CVE-2011-3841MEDIUM Cross-site scripting (XSS) vulnerability in uploadify/get_profile_avatar.php in the WP Symposium plugin before 11.12.08 for WordPress allows remote attackers to inject arbitrary we | Dec 27, 2011 | 4.3 | 17 | NO | NO |
CVE-2014-8809MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the WP Symposium plugin before 14.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) | Dec 24, 2014 | 4.3 | 14 | NO | NO |
CVE-2013-2695MEDIUM Cross-site scripting (XSS) vulnerability in invite.php in the WP Symposium plugin before 13.04 for WordPress allows remote attackers to inject arbitrary web script or HTML via the | Mar 28, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpsymposiumpro.
Media articles that mention a CVE ID that affects a product developed by Wpsymposiumpro — matched by CVE ID, not by vendor name.