Vulnerabilidades en stellarwp

134 resultados
Análisis Vexday

Com 81 CVEs catalogadas, o portfólio da StellarWP apresenta concentração notável em CWE-79 (Cross-Site Scripting) como tipo de falha mais recorrente, o que é característico de ecossistemas voltados a plugins e temas para plataformas web. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma CVE confirmada em uso por atacantes no momento, embora isso não elimine o risco operacional. O ponto de maior atenção é CVE-2024-5932, com score EPSS de 0,74 — valor elevado que indica probabilidade significativa de exploração —, devendo ser tratada com prioridade independentemente de ainda não constar no KEV. A presença de 7 vulnerabilidades críticas e 4 com PoC pública reforça a necessidade de ciclos de patching ágeis para quem mantém produtos StellarWP em produção.

CVE-2022-4974MEDIUMFreemius SDK <= 2.4.2 - Missing Authorization ChecksEPSS 0.4%CVE-2024-4209MEDIUMGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown TimerEPSS 0.4%CVE-2024-5977MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post ActionsEPSS 0.4%CVE-2024-1424MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2023-47183MEDIUMWordPress GiveWP plugin <= 2.33.1 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-13246MEDIUMGiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode AttributeEPSS 0.4%CVE-2024-10785MEDIUMGutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2024-3189MEDIUMGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2026-13704MEDIUMGiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa FormEPSS 0.4%CVE-2025-11517HIGHEvent Tickets and Registration <= 5.26.5 - Unauthenticated Ticket Payment BypassEPSS 0.4%CVE-2025-24753MEDIUMWordPress Kadence Blocks plugin <= 3.3.1 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-54697HIGHWordPress Kadence WooCommerce Email Designer Plugin <= 1.5.16 - Privilege Escalation VulnerabilityEPSS 0.4%CVE-2024-2261MEDIUMEvent Tickets and Registration <= 5.8.2 - Improper Authorization to Information DisclosureEPSS 0.4%CVE-2024-1053MEDIUMEvent Tickets and Registration <= 5.8.1 - Missing AuthorizationEPSS 0.4%CVE-2024-5941MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Missing Authorization to Authenticated (Subscriber+) Limited File DeletionEPSS 0.4%CVE-2026-12483HIGHLearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload HandlerEPSS 0.4%CVE-2024-1957MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.6.1 -- Authenticated(Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.4%CVE-2025-2331MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information ExposureEPSS 0.4%CVE-2026-15286MEDIUMGutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post PublicationEPSS 0.4%CVE-2023-6964HIGHGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF)EPSS 0.4%