SecAlerts
c

codepeople

Security Risk Profile

37
/100
low

Security Risk Score

Comprehensive risk assessment based on 90 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 19, 2014 to present

90
Total CVEs
30
Critical+High
0
Exploited
14
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
14
Critical/High
Risk Level
37/100
low
🆕 3Fresh (<7d)📈 4 in Last 30 Days

Severity Distribution

Critical
6
High
24
Medium
57
Low
3

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
18

Age Distribution

Common Weaknesses (CWE)

1
XSS
46
2
SQL Injection
9
3
CSRF
8
4
Input Validation
2
5
Code Injection
1

Most Affected Products

1. CodePeople Calculated Fields Form Wordpress13
2. CodePeople Appointment Booking Calendar Wordpress11
3. CodePeople Contact Form Email Wordpress10
4. CodePeople Calculated Fields Form7
5. CodePeople Wp Time Slots Booking Form Wordpress7

Recent Vulnerabilities

See more →
CVE-2026-100184
CVSS 4.7medium

Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Query Parameter via Text Area Predefined Value

Oct 1, 2026🔧 No Patch
CVE-2026-96573
CVSS 7.2high

Appointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer

Oct 1, 2026🔧 No Patch
CVE-2026-100179
CVSS 6.1medium

Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Parameter via setChoices()

Oct 1, 2026🔧 No Patch
CVE-2026-95529
CVSS 7.1EPSS 0%high

WordPress Calculated Fields Form plugin <= 5.5.1.1 - Cross Site Scripting (XSS) vulnerability

Sep 23, 2026🔧 No Patch
CVE-2026-13335
CVSS 6.4medium

CodePeople Post Map for Google Maps <= 1.2.6 - Authenticated (Contributor +) Stored Cross-Site Scripting via 'cpm_point' Post Meta

Jun 27, 2026🔧 No Patch
CVE-2026-32483
CVSS 6.5medium

WordPress Contact Form Email plugin <= 1.3.63 - Broken Access Control vulnerability

Mar 25, 2026🔧 No Patch
CVE-2026-25465
CVSS 6.5medium

WordPress CP Multi View Event Calendar plugin <= 1.4.36 - Cross Site Scripting (XSS) vulnerability

Mar 25, 2026🔧 No Patch
CVE-2026-25368
CVSS 6.5EPSS 0%medium

WordPress Calculated Fields Form plugin <= 5.4.4.1 - Broken Access Control vulnerability

Feb 19, 2026🔧 No Patch
CVE-2025-68850
CVSS 7.5high

WordPress Sell Downloads plugin <= 1.1.12 - Broken Access Control vulnerability

Jan 5, 2026🔧 No Patch
CVE-2025-64261
CVSS 5.4medium

WordPress Appointment Booking Calendar plugin <= 1.3.95 - Broken Access Control vulnerability

Nov 13, 2025🔧 No Patch

Monitor codepeople in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.