Vulnerabilities (CVE)

Filtered by vendor Wpdevart Subscribe
Total 23 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24464 1 Wpdevart 1 Youtube Embed\, Playlist And Popup 2024-02-04 3.5 LOW 5.4 MEDIUM
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue.
CVE-2018-10363 1 Wpdevart 1 Booking Calendar 2024-02-04 5.0 MEDIUM 7.5 HIGH
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.
CVE-2017-14125 1 Wpdevart 1 Responsive Image Gallery Gallery Album 2024-02-04 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.