Vulnerabilities in StellarWP

134 results
Vexday analysis

StellarWP apresenta 36 vulnerabilidades catalogadas, das quais apenas 2 são críticas e nenhuma está sob ataque ativo conhecido, indicando risco contido no curto prazo. A fraqueza dominante (CWE-862 - falta de autorização) sugere problemas estruturais em controle de acesso que demandam revisão. O ritmo de publicações é baixo (2 nos últimos 90 dias), refletindo uma superfície de exposição estável.

CVE-2024-12118MEDIUMThe Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2024-3714MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-66533MEDIUMWordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerabilityEPSS 0.3%CVE-2025-11227MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns DisclosureEPSS 0.3%CVE-2026-27056MEDIUMWordPress iThemes Sync plugin <= 3.2.8 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-5819MEDIUMGutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.45 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data AttributesEPSS 0.3%CVE-2024-4208MEDIUMGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typer EffectEPSS 0.3%CVE-2025-5144MEDIUMThe Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-12633HIGHBooking Calendar | Appointment Booking | Bookit <= 2.5.0 - Missing Authorization to Unauthenticated Stripe ConnectionEPSS 0.3%CVE-2023-4247MEDIUMGiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin deactivationEPSS 0.3%CVE-2025-13206HIGHGiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'EPSS 0.3%CVE-2025-12192MEDIUMThe Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2025-7221MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation UpdateEPSS 0.2%CVE-2023-4248MEDIUMGiveWP <= 2.33.3 - Cross-Site Request Forgery to Stripe Integration DeletionEPSS 0.2%CVE-2026-42643MEDIUMWordPress Image Widget plugin <= 4.4.11 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-5678MEDIUMKadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` ParameterEPSS 0.2%CVE-2025-14000MEDIUMMembership Plugin – Restrict Content <= 3.2.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodesEPSS 0.2%CVE-2024-12304MEDIUMGutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button LinkEPSS 0.2%CVE-2023-4246MEDIUMGiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin installationEPSS 0.2%CVE-2025-50046MEDIUMWordPress WPComplete plugin <= 2.9.5 - Cross Site Scripting (XSS) VulnerabilityEPSS 0.2%