Vulnerabilidades en StellarWP
127 resultadosAnálisis Vexday
StellarWP apresenta 36 vulnerabilidades catalogadas, das quais apenas 2 são críticas e nenhuma está sob ataque ativo conhecido, indicando risco contido no curto prazo. A fraqueza dominante (CWE-862 - falta de autorização) sugere problemas estruturais em controle de acesso que demandam revisão. O ritmo de publicações é baixo (2 nos últimos 90 dias), refletindo uma superfície de exposição estável.
CVE-2026-9273CRITICALMembership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account TakeoverEPSS 0.3%CVE-2026-12902MEDIUMKadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX ActionsEPSS 0.3%CVE-2026-3079MEDIUMLearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' ParameterEPSS 0.3%CVE-2025-66533MEDIUMWordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerabilityEPSS 0.3%CVE-2025-11228MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign AssociationEPSS 0.3%CVE-2026-15286MEDIUMGutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post PublicationEPSS 0.3%CVE-2024-5819MEDIUMGutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.45 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data AttributesEPSS 0.3%CVE-2024-4208MEDIUMGutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typer EffectEPSS 0.3%CVE-2023-4247MEDIUMGiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin deactivationEPSS 0.3%CVE-2025-12633HIGHBooking Calendar | Appointment Booking | Bookit <= 2.5.0 - Missing Authorization to Unauthenticated Stripe ConnectionEPSS 0.3%CVE-2025-4571MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And ModificationEPSS 0.3%CVE-2025-11227MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns DisclosureEPSS 0.3%CVE-2025-12192MEDIUMThe Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2025-5678MEDIUMKadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` ParameterEPSS 0.2%CVE-2025-13206HIGHGiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'EPSS 0.2%CVE-2023-4248MEDIUMGiveWP <= 2.33.3 - Cross-Site Request Forgery to Stripe Integration DeletionEPSS 0.2%CVE-2026-13246MEDIUMGiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode AttributeEPSS 0.2%CVE-2025-7221MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation UpdateEPSS 0.2%CVE-2023-4246MEDIUMGiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin installationEPSS 0.2%CVE-2024-12304MEDIUMGutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button LinkEPSS 0.2%