Vulnerabilidades en StellarWP
134 resultadosAnálisis Vexday
StellarWP apresenta 36 vulnerabilidades catalogadas, das quais apenas 2 são críticas e nenhuma está sob ataque ativo conhecido, indicando risco contido no curto prazo. A fraqueza dominante (CWE-862 - falta de autorização) sugere problemas estruturais em controle de acesso que demandam revisão. O ritmo de publicações é baixo (2 nos últimos 90 dias), refletindo uma superfície de exposição estável.
CVE-2026-2608MEDIUMGutenberg Blocks by Kadence Blocks <= 3.5.32 - Missing AuthorizationEPSS 0.3%CVE-2024-24888MEDIUMWordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.2.25 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.3%CVE-2026-18435MEDIUMKadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block AttributeEPSS 0.3%CVE-2026-77820MEDIUMWPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode AttributeEPSS 0.3%CVE-2024-35679HIGHWordPress GiveWP plugin <= 3.12.0 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-22633MEDIUMWordPress Give – Divi Donation Modules plugin <= 2.0.0 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2024-13457MEDIUMEvent Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information ExposureEPSS 0.3%CVE-2025-1291MEDIUMGutenberg Blocks by Kadence Blocks <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon'EPSS 0.3%CVE-2026-11357MEDIUMKadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData LocalizationEPSS 0.3%CVE-2024-5289MEDIUMGutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.42 - Authenticated (Contributor+) Stored Cross-Site Scripting in Google Maps WidgetEPSS 0.3%CVE-2024-2273MEDIUMGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.34 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-1304MEDIUMMembership Plugin – Restrict Content <= 3.2.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Invoice SettingsEPSS 0.3%CVE-2026-42642MEDIUMWordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-9655MEDIUMGutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon WidgetEPSS 0.3%CVE-2025-30794HIGHWordPress Event Tickets plugin <= 5.20.0 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-4571MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And ModificationEPSS 0.3%CVE-2025-13387HIGHKadence WooCommerce Email Designer <= 1.5.17 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-2826MEDIUMKadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media UploadEPSS 0.3%CVE-2026-1857MEDIUMGutenberg Blocks with AI by Kadence WP <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' ParameterEPSS 0.3%CVE-2025-11228MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign AssociationEPSS 0.3%