Vulnerability index

Browse CVEs

66 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Spectra MEDIUM 5.3
CVE-2023-23730

Improper Restriction of Excessive Authentication Attempts vulnerability in Brainstorm Force Spectra allows Functionality Bypass.This issue affects Sp…

Fix: 2.3.1+
Fix from $1,600 2024-06-03
Spectra MEDIUM 5.4
CVE-2024-4366

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘block_id’ parameter in versions u…

Fix: 2.13.1+
Fix from $1,600 2024-05-24
Custom Fonts MEDIUM 5.4
CVE-2024-1332

The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg file upload in all versions up t…

Fix: 2.1.5+
Fix from $1,600 2024-05-24
Elementor Header \& Footer Builder MEDIUM 5.4
CVE-2024-2618

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size attribute in all versions up to,…

Fix: 1.6.27+
Fix from $1,600 2024-05-24
Spectra MEDIUM 5.4
CVE-2024-1814

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial block in all …

Fix: 2.12.9+
Fix from $1,600 2024-05-23
Spectra MEDIUM 5.4
CVE-2024-1815

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Gallery block in al…

Fix: 2.12.9+
Fix from $1,600 2024-05-23
Ultimate Addons For Beaver Builder HIGH 8.8
CVE-2023-51398

Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Privilege Escalation.This issue affects Ult…

Fix: 1.35.15+
Fix from $1,950 2024-05-17
Ultimate Addons For Beaver Builder MEDIUM 6.5
CVE-2023-51401

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder a…

Fix: 1.35.14+
Fix from $1,600 2024-05-17
Elementor Header \& Footer Builder MEDIUM 5.4
CVE-2024-2619

The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient …

Fix: 1.6.27+
Fix from $1,600 2024-05-16
Elementor Header \& Footer Builder MEDIUM 5.4
CVE-2024-4634

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hfe_svg_mime_types’ function in vers…

Fix: 1.6.29+
Fix from $1,600 2024-05-16
Cards For Beaver Builder MEDIUM 5.4
CVE-2024-2305

The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the BootstrapCard link in all versions up to, and…

Fix: 1.1.3+
Fix from $1,600 2024-04-09
Spectra MEDIUM 5.4
CVE-2023-6486

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS metabox in all versions…

Fix: 2.10.4+
Fix from $1,600 2024-04-09
Ultimate Addons For Beaver Builder MEDIUM 5.4
CVE-2024-2144

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Separator widget in all…

Fix: 1.5.8+
Fix from $1,600 2024-03-30
Ultimate Addons For Beaver Builder MEDIUM 5.4
CVE-2024-2141

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions…

Fix: 1.5.8+
Fix from $1,600 2024-03-30
Ultimate Addons For Beaver Builder MEDIUM 5.4
CVE-2024-2142

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Info Table widget in all vers…

Fix: 1.5.8+
Fix from $1,600 2024-03-30
Ultimate Addons For Beaver Builder MEDIUM 5.4
CVE-2024-2143

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all version…

Fix: 1.5.8+
Fix from $1,600 2024-03-30
Ultimate Addons For Beaver Builder MEDIUM 5.4
CVE-2024-2140

The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Icons widget in all …

Fix: 1.5.8+
Fix from $1,600 2024-03-30
Spectra MEDIUM 6.5
CVE-2023-36679

Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.

Fix: 2.6.7+
Fix from $1,600 2024-03-28
Elementor Header \& Footer Builder MEDIUM 5.4
CVE-2024-1237

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flyout_layout attribute in all versio…

Fix: 1.6.25+
Fix from $1,600 2024-03-13
Ultimate Addons For Wpbakery Page Builder HIGH 8.8
CVE-2023-51402

Cross-Site Request Forgery (CSRF) vulnerability in Brain Storm Force Ultimate Addons for WPBakery Page Builder.This issue affects Ultimate Addons for…

Fix: after 3.19.17
Fix from $1,950 2023-12-29
Wp Remote Site Search MEDIUM 5.4
CVE-2023-51397

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force WP Remote Site Search allows S…

Fix: after 1.0.4
Fix from $1,600 2023-12-29
Astra HIGH 8.8
CVE-2023-49830

Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through …

Fix: after 4.3.1
Fix from $1,950 2023-12-29
Spectra MEDIUM 5.4
CVE-2023-49833

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra – WordPress Gutenberg …

Fix: 2.7.10+
Fix from $1,600 2023-12-14
Starter Templates MEDIUM 5.4
CVE-2023-41804

Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue a…

Fix: 3.2.5+
Fix from $1,600 2023-12-07
Schema HIGH 8.8
CVE-2023-36682

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro…

Fix: 2.7.8+
Fix from $1,950 2023-11-30
Cartflows HIGH 8.8
CVE-2023-36685

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC CartFlows Pro allows Cross Site Request Forgery.This issue affects CartFlo…

Fix: after 1.11.12
Fix from $1,950 2023-11-30
Ultimate Addons For Wpbakery Page Builder MEDIUM 5.4
CVE-2023-46211

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 …

Fix: 3.19.15+
Fix from $1,600 2023-10-27
Schema HIGH 8.8
CVE-2023-25058

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions.

Fix: 1.6.6+
Fix from $1,950 2023-05-26
Starter Templates HIGH 8.8
CVE-2022-46851

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions.

Fix: 3.1.21+
Fix from $1,950 2023-05-23
Spectra MEDIUM 5.4
CVE-2020-36656

The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stor…

Fix: 1.15.0+
Fix from $1,600 2023-02-21