Vulnerabilidades en StellarWP

134 resultados
Análisis Vexday

StellarWP apresenta 36 vulnerabilidades catalogadas, das quais apenas 2 são críticas e nenhuma está sob ataque ativo conhecido, indicando risco contido no curto prazo. A fraqueza dominante (CWE-862 - falta de autorização) sugere problemas estruturais em controle de acesso que demandam revisão. O ritmo de publicações é baixo (2 nos últimos 90 dias), refletindo uma superfície de exposição estável.

CVE-2024-5941MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Missing Authorization to Authenticated (Subscriber+) Limited File DeletionEPSS 0.4%CVE-2026-12483HIGHLearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload HandlerEPSS 0.4%CVE-2026-2633MEDIUMGutenberg Blocks with AI by Kadence WP <= 3.6.1 - Missing Authorization to Authenticated (Contributor+) Unauthorized Media UploadEPSS 0.4%CVE-2025-2331MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information ExposureEPSS 0.4%CVE-2024-1957MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.6.1 -- Authenticated(Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.4%CVE-2026-15286MEDIUMGutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post PublicationEPSS 0.4%CVE-2023-6964HIGHGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF)EPSS 0.4%CVE-2024-31432MEDIUMWordPress Restrict Content plugin <= 3.2.8 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-48246MEDIUMWordPress The Events Calendar plugin <= 6.11.2.1 - Broken Access Control VulnerabilityEPSS 0.4%CVE-2026-18062MEDIUMKadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image ContentEPSS 0.4%CVE-2026-5510MEDIUMGiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode AttributesEPSS 0.4%CVE-2026-14987MEDIUMGiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template SettingEPSS 0.4%CVE-2024-27987HIGHWordPress Give plugin <= 3.3.1 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2026-1321HIGHMembership Plugin – Restrict Content <= 3.2.20 - Unauthenticated Privilege Escalation via 'rcp_level'EPSS 0.4%CVE-2025-9807HIGHThe Events Calendar <= 6.15.1 - Unauthenticated SQL InjectionEPSS 0.3%CVE-2025-49906MEDIUMWordPress WPComplete plugin <= 2.9.5.3 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-4136MEDIUMMembership Plugin – Restrict Content <= 3.2.24 - Unvalidated Redirect in Password Reset Flow via rcp_redirectEPSS 0.3%CVE-2024-2919MEDIUMGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via CountUp WidgetEPSS 0.3%CVE-2024-6551MEDIUMGiveWP <= 3.15.1 - Unauthenticated Full Path DisclosureEPSS 0.3%CVE-2024-4481MEDIUMGutenberg Blocks with AI by Kadence WP <= 3.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block LinkEPSS 0.3%