Wpvar maintains a niche WordPress plugin portfolio centered on the WP Shamsi calendar and localization product, which serves a specialized but non-trivial user base. The observed vulnerability surface centers on access-control and request-validation weaknesses, including missing authorization checks and cross-site request forgery conditions that are characteristic of plugin-layer security issues. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpvar over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0335MEDIUM The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment. | Mar 27, 2023 | 6.5 | 21 | NO | NO |
CVE-2022-38058MEDIUM Authenticated (subscriber+) Plugin Setting change vulnerability in WP Shamsi plugin <= 4.1.1 at WordPress. | Sep 9, 2022 | 4.3 | 18 | NO | NO |
CVE-2022-4555MEDIUM The WP Shamsi plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the deactivate() function hooked via init() in versions up to, and inc | Dec 16, 2022 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpvar.
Media articles that mention a CVE ID that affects a product developed by Wpvar — matched by CVE ID, not by vendor name.