Vulnerabilities in StellarWP

134 results
Vexday analysis

StellarWP apresenta 36 vulnerabilidades catalogadas, das quais apenas 2 são críticas e nenhuma está sob ataque ativo conhecido, indicando risco contido no curto prazo. A fraqueza dominante (CWE-862 - falta de autorização) sugere problemas estruturais em controle de acesso que demandam revisão. O ritmo de publicações é baixo (2 nos últimos 90 dias), refletindo uma superfície de exposição estável.

CVE-2024-9130HIGHGiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Authenticated (GiveWP Manager+) SQL Injection via order ParameterEPSS 0.7%CVE-2024-30229HIGHWordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-2025MEDIUMGive <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings FunctionEPSS 0.6%CVE-2025-39557CRITICALWordPress Kadence WooCommerce Email Designer plugin <= 1.5.14 - Arbitrary File Upload vulnerabilityEPSS 0.6%CVE-2024-4034MEDIUMVirtue <= 3.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post AuthorEPSS 0.6%CVE-2023-6557MEDIUMThe Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information ExposureEPSS 0.6%CVE-2025-8620MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data ExposureEPSS 0.5%CVE-2024-1541MEDIUMGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.23 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2024-1999MEDIUMGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial WidgetEPSS 0.5%CVE-2026-3585HIGHThe Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_importEPSS 0.5%CVE-2026-9273CRITICALMembership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account TakeoverEPSS 0.5%CVE-2024-23500HIGHWordPress Kadence Blocks plugin <= 3.2.19 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.5%CVE-2024-4863MEDIUMGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via titleFont ParameterEPSS 0.5%CVE-2024-5939MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information ExposureEPSS 0.5%CVE-2024-12581MEDIUMKadence Blocks <= 3.2.53 - Authenticated (Admin+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2026-12902MEDIUMKadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX ActionsEPSS 0.5%CVE-2024-5940MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings UpdateEPSS 0.5%CVE-2026-3174HIGHEvent Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials UpdateEPSS 0.5%CVE-2026-3079MEDIUMLearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' ParameterEPSS 0.5%CVE-2025-14844HIGHMembership Plugin – Restrict Content <= 3.2.16 - Missing Authentication to Insecure Direct Object Reference and Sensitive Information ExposureEPSS 0.5%