SecAlerts
w

wpdevart

Security Risk Profile

27
/100
low

Security Risk Score

Comprehensive risk assessment based on 49 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from September 25, 2017 to present

49
Total CVEs
18
Critical+High
0
Exploited
12
Unpatched

Threat Assessment

Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
12
Critical/High
Risk Level
27/100
low
📈 1 in Last 30 Days

Severity Distribution

Critical
5
High
13
Medium
29
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
XSS
24
2
CSRF
10
3
SQL Injection
6
4
Malicious File Upload
1
5
Input Validation
1

Most Affected Products

1. WpDevArt Booking Calendar Wordpress8
2. WpDevArt Gallery Wordpress7
3. WpDevArt Booking calendar, Appointment Booking System5
4. WordPress Gallery – Image and Video Gallery with Thumbnails3
5. WpDevArt Organization Chart Wordpress3

Recent Vulnerabilities

See more →
CVE-2026-8840
CVSS 5.3EPSS 0%medium

Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action

Aug 15, 2026🔧 No Patch
CVE-2026-57778
CVSS 5.3medium

WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Broken Access Control vulnerability

Jul 13, 2026🔧 No Patch
CVE-2026-24597
CVSS 4.3medium

WordPress Organization chart plugin <= 1.7.5 - Cross Site Request Forgery (CSRF) vulnerability

May 25, 2026🔧 No Patch
CVE-2026-25435
CVSS 7.1high

WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Cross Site Scripting (XSS) vulnerability

Mar 25, 2026🔧 No Patch
CVE-2025-67574
CVSS 5.3medium

WordPress Booking calendar, Appointment Booking System plugin <= 3.2.30 - Broken Access Control vulnerability

Dec 9, 2025🔧 No Patch
CVE-2025-62886
CVSS 7.1high

WordPress Pricing Table builder plugin <= 1.5.3 - Cross Site Request Forgery (CSRF) vulnerability

Oct 27, 2025🔧 No Patch
CVE-2025-47443
CVSS 6.5EPSS 0%medium

WordPress Widget Countdown plugin <= 2.7.4 - Cross Site Scripting (XSS) Vulnerability

May 7, 2025
CVE-2025-24719
CVSS 6.5EPSS 0%medium

WordPress Widget Countdown plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability

Jan 24, 2025
CVE-2023-45631
CVSS 5.4medium

WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerability

Jan 2, 2025🔧 No Patch
CVE-2024-10856
CVSS 6.5medium

Booking Calendar WpDevArt <= 3.2.19 - Authenticated (Contributor+) SQL Injection

Dec 24, 2024

Monitor wpdevart in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.