Vulnerabilities > Wpdevart > High

DATE CVE VULNERABILITY TITLE RISK
2024-06-08 CVE-2024-35750 Unspecified vulnerability in Wpdevart Gallery
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevart Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.
network
low complexity
wpdevart
8.8
2023-10-16 CVE-2023-45629 Cross-Site Request Forgery (CSRF) vulnerability in Wpdevart Gallery - Image and Video Gallery With Thumbnails
Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions.
network
low complexity
wpdevart CWE-352
8.8
2023-06-05 CVE-2023-0900 Unspecified vulnerability in Wpdevart Pricing Table Builder 1.1.5/1.1.6
The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admins.
network
low complexity
wpdevart
7.2
2023-02-23 CVE-2023-24384 Cross-Site Request Forgery (CSRF) vulnerability in Wpdevart Organization Chart
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions.
network
low complexity
wpdevart CWE-352
8.8
2018-06-13 CVE-2018-10363 Improper Input Validation vulnerability in Wpdevart Booking Calendar 2.2.2
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress.
network
low complexity
wpdevart CWE-20
7.5