Vulnerabilidades en bplugins

79 resultados
CVE-2026-11402MEDIUMServices Section Block <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Block AttributeEPSS 0.2%CVE-2025-22815MEDIUMWordPress Button Block plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-54734MEDIUMWordPress B Slider Plugin <= 1.1.30 - Broken Access Control VulnerabilityEPSS 0.2%CVE-2025-54708MEDIUMWordPress B Blocks Plugin <= 2.0.5 - Cross Site Scripting (XSS) VulnerabilityEPSS 0.2%CVE-2026-1389MEDIUMDocument Embedder <= 2.0.4 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Document Library Entry DeletionEPSS 0.2%CVE-2025-12388MEDIUMB Carousel Block – Responsive Image and Content Carousel <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request ForgeryEPSS 0.2%CVE-2025-13999HIGHHTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player 2.4.0 - 2.5.1 - Unauthenticated Server-Side Request ForgeryEPSS 0.2%CVE-2025-66110MEDIUMWordPress Tiktok Feed plugin <= 1.0.23 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-27416MEDIUMWordPress PDF Poster plugin <= 2.4.1 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-1228MEDIUMTimeline Block <= 1.3.3 - Insecure Direct Object Reference to Authenticated (Author+) Private Timeline Exposure via Shortcode AttributeEPSS 0.2%CVE-2025-54051MEDIUMWordPress LightBox Block plugin <= 1.1.30 - Cross Site Scripting (XSS) VulnerabilityEPSS 0.2%CVE-2025-12376MEDIUMIcon List Block – Add Icon-Based Lists with Custom Styles <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request ForgeryEPSS 0.2%CVE-2026-32359MEDIUMWordPress Icon List Block plugin <= 1.2.3 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-27326MEDIUMWordPress Video Gallery Block plugin <= 1.1.0 - Cross Site Scripting (XSS) VulnerabilityEPSS 0.2%CVE-2026-24520MEDIUMWordPress Tiktok Feed plugin <= 1.0.24 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-40729MEDIUMWordPress 3D viewer – Embed 3D Models plugin <= 1.8.5 - Broken Access Control vulnerabilityEPSS 0.1%CVE-2025-54694MEDIUMWordPress Button Block Plugin plugin <= 1.2.0 - Cross Site Request Forgery (CSRF) VulnerabilityEPSS 0.1%CVE-2026-24383MEDIUMWordPress B Slider plugin <= 2.0.6 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.1%CVE-2026-53736MEDIUMEasy Twitter Feeds before 1.2.13 Cross-Site Request Forgery via duplicate_post ActionEPSS 0.1%