Vulnerabilities in StellarWP

134 results
Vexday analysis

StellarWP apresenta 36 vulnerabilidades catalogadas, das quais apenas 2 são críticas e nenhuma está sob ataque ativo conhecido, indicando risco contido no curto prazo. A fraqueza dominante (CWE-862 - falta de autorização) sugere problemas estruturais em controle de acesso que demandam revisão. O ritmo de publicações é baixo (2 nos últimos 90 dias), refletindo uma superfície de exposição estável.

CVE-2024-11090MEDIUMMembership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.5%CVE-2026-12904MEDIUMKadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' ParameterEPSS 0.5%CVE-2024-5648MEDIUMLearnDash LMS - Reports Free <= 1.8.2.1 - Missing Authorization to Plugin Settings UpdateEPSS 0.4%CVE-2025-1402MEDIUMEvent Tickets and Registration <= 5.19.1.1 - Missing Authorization to Ticket DeletionEPSS 0.4%CVE-2022-4974MEDIUMFreemius SDK <= 2.4.2 - Missing Authorization ChecksEPSS 0.4%CVE-2024-4209MEDIUMGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown TimerEPSS 0.4%CVE-2024-5977MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post ActionsEPSS 0.4%CVE-2024-1424MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2023-47183MEDIUMWordPress GiveWP plugin <= 2.33.1 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-13246MEDIUMGiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode AttributeEPSS 0.4%CVE-2026-2694MEDIUMThe Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST APIEPSS 0.4%CVE-2024-10785MEDIUMGutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2024-3189MEDIUMGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2026-13704MEDIUMGiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa FormEPSS 0.4%CVE-2025-11517HIGHEvent Tickets and Registration <= 5.26.5 - Unauthenticated Ticket Payment BypassEPSS 0.4%CVE-2025-24753MEDIUMWordPress Kadence Blocks plugin <= 3.3.1 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-54697HIGHWordPress Kadence WooCommerce Email Designer Plugin <= 1.5.16 - Privilege Escalation VulnerabilityEPSS 0.4%CVE-2024-2261MEDIUMEvent Tickets and Registration <= 5.8.2 - Improper Authorization to Information DisclosureEPSS 0.4%CVE-2024-1053MEDIUMEvent Tickets and Registration <= 5.8.1 - Missing AuthorizationEPSS 0.4%CVE-2026-32546HIGHWordPress Restrict Content plugin <= 3.2.22 - Broken Access Control vulnerabilityEPSS 0.4%