wpdevart Vulnerabilities and Affected Products
Vulnerabilities associated with poll\,_survey\,_questionnaire_and_voting_system.
Products
Clear product- Booking calendar, Appointment Booking System12 vulnerabilities
- Responsive Image Gallery, Gallery Album5 vulnerabilities
- Organization chart4 vulnerabilities
- booking_calendar3 vulnerabilities
- Gallery – Image and Video Gallery with Thumbnails3 vulnerabilities
- Contact Form Builder, Contact Widget2 vulnerabilities
- Responsive Vertical Icon Menu2 vulnerabilities
- Widget Countdown2 vulnerabilities
- YouTube Embed, Playlist and Popup by WpDevArt2 vulnerabilities
- Booking Calendar Pro WpDevArt1 vulnerability
- Coming soon and Maintenance mode1 vulnerability
- Contact Form Builder1 vulnerability
- Countdown and CountUp, WooCommerce Sales Timer1 vulnerability
- Countdown and CountUp, WooCommerce Sales Timers1 vulnerability
- Countdown Timer – Widget Countdown1 vulnerability
- Image and Video Lightbox, Image PopUp1 vulnerability
- Poll, Survey, Questionnaire and Voting system1 vulnerability
- Poll, Survey, Questionnaire and Voting system (WordPress plugin)1 vulnerability
- poll\,_survey\,_questionnaire_and_voting_system1 vulnerability
- Pricing Table builder1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-24442CRITICAL | Poll, Survey, Questionnaire and Voting system < 1.5.3 - Unauthenticated Blind SQL InjectionThe Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks | CVSS9.8v3.1 | EPSS46.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |