Vulnerabilidades em stellarwp

134 resultados
Análise Vexday

Com 81 CVEs catalogadas, o portfólio da StellarWP apresenta concentração notável em CWE-79 (Cross-Site Scripting) como tipo de falha mais recorrente, o que é característico de ecossistemas voltados a plugins e temas para plataformas web. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma CVE confirmada em uso por atacantes no momento, embora isso não elimine o risco operacional. O ponto de maior atenção é CVE-2024-5932, com score EPSS de 0,74 — valor elevado que indica probabilidade significativa de exploração —, devendo ser tratada com prioridade independentemente de ainda não constar no KEV. A presença de 7 vulnerabilidades críticas e 4 com PoC pública reforça a necessidade de ciclos de patching ágeis para quem mantém produtos StellarWP em produção.

CVE-2025-1291MEDIUMGutenberg Blocks by Kadence Blocks <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon'EPSS 0.3%CVE-2024-9655MEDIUMGutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon WidgetEPSS 0.3%CVE-2025-30794HIGHWordPress Event Tickets plugin <= 5.20.0 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-4571MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And ModificationEPSS 0.3%CVE-2026-2826MEDIUMKadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media UploadEPSS 0.3%CVE-2025-13387HIGHKadence WooCommerce Email Designer <= 1.5.17 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-1857MEDIUMGutenberg Blocks with AI by Kadence WP <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' ParameterEPSS 0.3%CVE-2025-11228MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign AssociationEPSS 0.3%CVE-2024-12118MEDIUMThe Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2024-3714MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-66533MEDIUMWordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerabilityEPSS 0.3%CVE-2026-9273CRITICALMembership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account TakeoverEPSS 0.3%CVE-2025-11227MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns DisclosureEPSS 0.3%CVE-2026-3079MEDIUMLearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' ParameterEPSS 0.3%CVE-2026-3174HIGHEvent Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials UpdateEPSS 0.3%CVE-2024-4208MEDIUMGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typer EffectEPSS 0.3%CVE-2024-5819MEDIUMGutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.45 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data AttributesEPSS 0.3%CVE-2026-5510MEDIUMGiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode AttributesEPSS 0.3%CVE-2025-5144MEDIUMThe Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-12633HIGHBooking Calendar | Appointment Booking | Bookit <= 2.5.0 - Missing Authorization to Unauthenticated Stripe ConnectionEPSS 0.3%