Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Siteorigin Widgets Bundle MEDIUM 5.4
CVE-2025-5585

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM Element Attribute in all versi…

Fix: 1.69.0+
Fix from $1,600 2025-06-25
Page Builder MEDIUM 5.4
CVE-2025-1459

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Embedded Video(PB) widget in all versions up…

Fix: 2.31.5+
Fix from $1,600 2025-03-01
Page Builder MEDIUM 5.4
CVE-2024-12240

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label parameter in all versions up to, a…

Fix: 2.31.1+
Fix from $1,600 2025-01-14
Siteorigin Widgets Bundle HIGH 8.8
CVE-2024-54268

Missing Authorization vulnerability in Greg - SiteOrigin SiteOrigin Widgets Bundle so-widgets-bundle allows Exploiting Incorrectly Configured Access …

Fix: 1.64.1+
Fix from $1,950 2024-12-13
Siteorigin Widgets Bundle MEDIUM 5.4
CVE-2024-5901

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget in all versions up to, and …

Fix: 1.62.3+
Fix from $1,600 2024-07-30
Siteorigin Widgets Bundle MEDIUM 5.4
CVE-2024-5090

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SiteOrigin Blog Widget in all versio…

Fix: 1.62.0+
Fix from $1,600 2024-06-11
Siteorigin Widgets Bundle MEDIUM 5.4
CVE-2024-4362

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all…

Fix: 1.58.8+
Fix from $1,600 2024-05-22
Page Builder MEDIUM 5.4
CVE-2024-4361

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in al…

Fix: 2.29.16+
Fix from $1,600 2024-05-21
Page Builder MEDIUM 5.4
CVE-2024-2202

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image widget in all versions up to, a…

Fix: 2.29.7+
Fix from $1,600 2024-03-23
Siteorigin Widgets Bundle MEDIUM 5.4
CVE-2024-1723

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and inc…

Fix: 1.58.8+
Fix from $1,600 2024-03-13
Siteorigin Widgets Bundle MEDIUM 5.4
CVE-2024-1070

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the features attribute in all versions up to, and…

Fix: 1.58.3+
Fix from $1,600 2024-02-29
Siteorigin Widgets Bundle MEDIUM 5.4
CVE-2024-1058

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the onclick parameter in all versions up to, and …

Fix: 1.58.4+
Fix from $1,600 2024-02-29
Siteorigin Widgets Bundle MEDIUM 5.4
CVE-2024-0961

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the code editor in all versions up to, and includ…

Fix: after 1.58.1
Fix from $1,600 2024-02-05
Siteorigin Widgets Bundle HIGH 7.2
CVE-2023-6295

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include functio…

Fix: 1.51.0+
Fix from $1,950 2023-12-18
Page Builder HIGH 8.8
CVE-2020-13643

An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification…

Fix: 2.10.16+
Fix from $1,950 2020-05-28
Page Builder HIGH 8.8
CVE-2020-13642

An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce …

Fix: 2.10.16+
Fix from $1,950 2020-05-28