Vulnerabilidades em stellarwp

127 resultados
Análise Vexday

Com 81 CVEs catalogadas, o portfólio da StellarWP apresenta concentração notável em CWE-79 (Cross-Site Scripting) como tipo de falha mais recorrente, o que é característico de ecossistemas voltados a plugins e temas para plataformas web. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma CVE confirmada em uso por atacantes no momento, embora isso não elimine o risco operacional. O ponto de maior atenção é CVE-2024-5932, com score EPSS de 0,74 — valor elevado que indica probabilidade significativa de exploração —, devendo ser tratada com prioridade independentemente de ainda não constar no KEV. A presença de 7 vulnerabilidades críticas e 4 com PoC pública reforça a necessidade de ciclos de patching ágeis para quem mantém produtos StellarWP em produção.

CVE-2024-5932CRITICALGiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code ExecutionEPSS 74.3%CVE-2024-8275CRITICALThe Events Calendar <= 6.6.4 - Unauthenticated SQL InjectionEPSS 49.5%CVE-2024-8353CRITICALGiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object InjectionEPSS 28.7%CVE-2025-12197HIGHThe Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via sEPSS 17.1%CVE-2024-6931HIGHThe Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site ScriptingEPSS 15.3%CVE-2024-1208MEDIUMLearnDash LMS <= 4.10.2 - Sensitive Information Exposure via APIEPSS 5.3%CVE-2024-1209MEDIUMLearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignmentsEPSS 2.4%CVE-2023-3105HIGHLearnDash LMS <= 4.6.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password ChangeEPSS 2.2%CVE-2024-1210MEDIUMLearnDash LMS <= 4.10.1 - Sensitive Information Exposure via APIEPSS 2.0%CVE-2023-2834CRITICALBookIt <= 2.3.7 - Authentication BypassEPSS 1.9%CVE-2025-0912CRITICALGiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object InjectionEPSS 1.4%CVE-2024-9634CRITICALGiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code ExecutionEPSS 1.4%CVE-2024-12877CRITICALGiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object InjectionEPSS 1.3%CVE-2022-2117MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 - Sensitive Information DisclosureEPSS 1.1%CVE-2023-47668MEDIUMWordPress Restrict Content Plugin <= 3.2.7 is vulnerable to Sensitive Data ExposureEPSS 1.0%CVE-2025-22777CRITICALWordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerabilityEPSS 0.9%CVE-2025-9808MEDIUMThe Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information DisclosureEPSS 0.8%CVE-2024-0598MEDIUMGutenberg Blocks by Kadence Blocks <= 3.2.17 - Authenticated(Editor+) Stored Cross-Site Scripting via Contact Form Message SettingsEPSS 0.7%CVE-2024-9130HIGHGiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Authenticated (GiveWP Manager+) SQL Injection via order ParameterEPSS 0.7%CVE-2024-30229HIGHWordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerabilityEPSS 0.6%