Filtered by vendor Wpdevart
Subscribe
Total
23 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-24464 | 1 Wpdevart | 1 Youtube Embed\, Playlist And Popup | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue. | |||||
CVE-2018-10363 | 1 Wpdevart | 1 Booking Calendar | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices. | |||||
CVE-2017-14125 | 1 Wpdevart | 1 Responsive Image Gallery Gallery Album | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php. |