Brainstormforce
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Brainstormforce product.
RSS Feeds for Brainstormforce security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Brainstormforce products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Brainstormforce Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 12 vulnerabilities in Brainstormforce with an average score of 6.8 out of ten. Last year, in 2025 Brainstormforce had 20 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Brainstormforce in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.77.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 12 | 6.84 |
| 2025 | 20 | 6.07 |
| 2024 | 58 | 6.38 |
| 2023 | 17 | 5.91 |
| 2022 | 0 | 0.00 |
| 2021 | 4 | 6.50 |
| 2020 | 1 | 6.50 |
| 2019 | 1 | 0.00 |
It may take a day or so for new Brainstormforce vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Brainstormforce Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-15787 | Jul 22, 2026 |
XSS in Ultimate Addons for Elementor Nav Menu Widget (<=2.9.1)The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post, applied on save for users without unfiltered_html, does not neutralize HTML-entity-encoded payloads stored inside data-* attributes on kses-allowed elements, as the browser decodes these values client-side before jQuery .html() renders them as markup. |
|
| CVE-2026-12900 | Jul 20, 2026 |
Spectra Gutenberg Blocks WP Stored XSS <=2.19.28The Spectra Gutenberg Blocks Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2026-15288 | Jul 10, 2026 |
SureForms WP Plugin <=2.2.1 Improper Input Validation in Payment IntentsThe SureForms Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly from user-controlled POST data in the 'create_payment_intent' and 'create_subscription_intent' functions without validating it against the form's configured price. This makes it possible for unauthenticated attackers to modify the payment amount to any arbitrary value when submitting a Stripe payment form, potentially purchasing products or services at significantly reduced prices. |
|
| CVE-2019-25763 | Jun 20, 2026 |
Auth Bypass via Social Media Login in WP Ultimate Addons <1.2.4.1WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a valid administrator email address, and a valid nonce to obtain session cookies and authenticate as that user. |
|
| CVE-2026-7465 | May 30, 2026 |
WordPress Spectra Gutenberg Blocks RCE up to v2.19.25 via block renderingThe Spectra Gutenberg Blocks Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation requires a two-block payload embedded in post content: the first block registers a fake uagb/-prefixed block type with an attacker-specified render_callback, and the second block of the same fake type triggers invocation of that callback via call_user_func() during sequential block rendering in the same page request. |
|
| CVE-2026-9065 | May 20, 2026 |
SQLi in SureCart <4.2.1 via REST API /v1/integrations (UNION extraction)SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'model_id', 'integration_id', 'provider') on the REST API endpoint '/surecart/v1/integrations/{id}'. The root cause is a flawed escaping bypass in the query builder ('wp-query-builder'). Values passed to the 'where()' method are only sanitized via '$wpdb->prepare()' when they do **not** contain a dot ('.') or the WordPress table prefix ('wp_'). By including a dot anywhere in the payload, an attacker completely bypasses the escaping logic and injects arbitrary SQL into the 'WHERE' clause, allowing full UNION-based extraction of the database. |
|
| CVE-2026-4987 | Mar 28, 2026 |
Payment Amount Bypass in SureForms 2.5.2 (form_id=0)The SureForms Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.5.2. This is due to the create_payment_intent() function performing a payment validation solely based on the value of a user-controlled parameter. This makes it possible for unauthenticated attackers to bypass configured form payment-amount validation and create underpriced payment/subscription intents by setting form_id to 0. |
|
| CVE-2026-3534 | Mar 11, 2026 |
Astra WP Theme <=4.12.3 Stored XSS via ast-page/ast-content metaThe Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-content-background-meta` post meta fields in all versions up to, and including, 4.12.3. This is due to insufficient input sanitization on meta registration and missing output escaping in the `astra_get_responsive_background_obj()` function for four CSS-context sub-properties (`background-color`, `background-image`, `overlay-color`, `overlay-gradient`). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2026-28038 | Mar 05, 2026 |
Missing Auth in Brainstorm Force UAPB <=3.21.1 Allows Access ExploitMissing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through <= 3.21.1. |
|
| CVE-2026-24982 | Feb 03, 2026 |
Spectra <=2.19.17 Missing Auth VulnerabilityMissing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.17. |
|
| CVE-2026-0950 | Feb 03, 2026 |
Spectra Gutenberg Blocks WP Plugin 2.19.17 Info Disclosure via post excerptsThe Spectra Gutenberg Blocks Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.19.17. This is due to the plugin failing to check `post_password_required()` before rendering post excerpts in the `render_excerpt()` function and the `uagb_get_excerpt()` helper function. This makes it possible for unauthenticated attackers to read excerpts of password-protected posts by simply viewing any page that contains a Spectra Post Grid, Post Masonry, Post Carousel, or Post Timeline block. |
|
| CVE-2025-14351 | Jan 20, 2026 |
WordPress Custom Fonts plugin <=2.1.16 missing capability check allows file deletionThe Custom Fonts Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'BCF_Google_Fonts_Compatibility' class constructor function in all versions up to, and including, 2.1.16. This makes it possible for unauthenticated attackers to delete font directory and rewrite theme.json file. |
|
| CVE-2025-14855 | Dec 21, 2025 |
WP SureForms <=2.2.0 Stored XSS via Form FieldsThe SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2023-23729 | Dec 09, 2025 |
Missing Auth in Brainstorm Force Spectra <=2.3.0Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0. |
|
| CVE-2025-13065 | Dec 06, 2025 |
WordPress Starter Templates <4.4.41 AFU via WXR double-extThe Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. |
|
| CVE-2025-13516 | Dec 02, 2025 |
SureMail SMTP Email Logs Plugin v1.9.0 Unrestricted File Upload RCE on Nginx/IISThe SureMail SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type in versions up to and including 1.9.0. This is due to the plugin's save_file() function in inc/emails/handler/uploads.php which duplicates all email attachments to a web-accessible directory (wp-content/uploads/suremails/attachments/) without validating file extensions or content types. Files are saved with predictable names derived from MD5 hashes of their content. While the plugin attempts to protect this directory with an Apache .htaccess file to disable PHP execution, this protection is ineffective on nginx, IIS, and Lighttpd servers, or on misconfigured Apache installations. This makes it possible for unauthenticated attackers to achieve Remote Code Execution by uploading malicious PHP files through any public form that emails attachments, calculating the predictable filename, and directly accessing the file to execute arbitrary code granted they are exploiting a site running on an affected web server configuration. |
|
| CVE-2025-12535 | Nov 19, 2025 |
SureForms WP Plugin <=1.13.1 CSRF Bypass via wp_rest nonceThe SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the plugin distributing generic WordPress REST API nonces (wp_rest) to unauthenticated users via the 'wp_ajax_nopriv_rest-nonce' action. While the plugin legitimately needs to support unauthenticated form submissions, it incorrectly uses generic REST nonces instead of form-specific nonces. This makes it possible for unauthenticated attackers to bypass CSRF protection on REST API endpoints that rely solely on nonce verification without additional authentication checks, allowing them to trigger unauthorized actions such as the plugin's own post-submission hooks and potentially other plugins' REST endpoints. |
|
| CVE-2025-12536 | Nov 13, 2025 |
WordPress SureForms 1.13.1 or earlier Sensitive Info ExposureThe SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. This makes it possible for unauthenticated attackers to extract sensitive data including email notification configurations, which frequently contain vendor-provided CRM/help desk dropbox addresses, CC/BCC recipients, and notification templates that can be abused to inject malicious data into downstream systems. |
|
| CVE-2025-11162 | Nov 05, 2025 |
Spectra Gutenberg Blocks 2.19.14: Stored XSS via Custom CSSThe Spectra Gutenberg Blocks Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2.19.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2025-10732 | Oct 14, 2025 |
Sensitive Info Disclosure in SureForms 1.12.1 via /srfm-global-settings APIThe SureForms Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. This makes it possible for authenticated attackers, with contributor-level access and above, to retrieve sensitive information including API keys for Google reCAPTCHA, Cloudflare Turnstile, hCaptcha, admin email addresses, and security-related form settings. |
|
| CVE-2025-10489 | Sep 20, 2025 |
WordPress SureForms1.12: Unauthorized Form Creation via Capability CheckThe SureForms Drag and Drop Contact Form Builder Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to create forms when the user interface specifically prohibits it. |
|
| CVE-2025-8488 | Aug 02, 2025 |
Auth Data Mod via missing cap check before v2.4.6 – Ultimate AddonsThe Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the compatibility option setting. |
|
| CVE-2025-5921 | Aug 01, 2025 |
Reflected XSS in SureForms WordPress plugin <1.7.2The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users. |
|
| CVE-2025-6742 | Jul 09, 2025 |
PHP Obj Inject in SureForms Drag&Drop Builder <=1.7.3 via delete_entry_files()The SureForms Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.3 via the use of file_exists() in the delete_entry_files() function without restriction on the path provided. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. |
|
| CVE-2025-6691 | Jul 09, 2025 |
SureForms DP FD Deletion RCE via delete_entry_files() before 1.7.3The SureForms Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). |
|
| CVE-2025-3514 | May 02, 2025 |
SureForms WP Plugin <1.4.4 Stored XSS via Form SettingsThe SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). |
|
| CVE-2025-3513 | May 02, 2025 |
Stored XSS via Unsanitized Form Settings in SureForms WP <1.4.4The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). |
|
| CVE-2025-3471 | Apr 30, 2025 |
WordPress SureForms <1.4.4 REST API Auth BypassThe SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action |
|
| CVE-2025-1784 | Mar 26, 2025 |
Spectra WordPress Gutenberg Blocks XSS via uagb – <2.19.0The Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uagb block in all versions up to, and including, 2.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2025-24568 | Jan 24, 2025 |
CSRF in Brainstorm Force Starter Templates <=4.4.9Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates astra-sites allows Cross Site Request Forgery.This issue affects Starter Templates: from n/a through <= 4.4.9. |
|
| CVE-2024-12713 | Jan 08, 2025 |
WP Plugin SureForms 1.2.2 Info Exposure via handle_export_form missing checkThe SureForms Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password protected, private, or draft posts that they should not have access to. |
|
| CVE-2024-56274 | Jan 07, 2025 |
Stored XSS in Brainstorm Force Astra Widgets before v1.2.15Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets astra-widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through <= 1.2.15. |
|
| CVE-2024-11230 | Dec 23, 2024 |
Elementor Header & Footer Builder Plugin: Stored XSS via Size ParameterThe Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size parameter in all versions up to, and including, 1.6.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2023-23825 | Dec 09, 2024 |
Missing Auth: Spectra <=2.3.0 misconfigured ACLMissing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0. |
|
| CVE-2023-23834 | Dec 09, 2024 |
Brainstorm Force Spectra <2.3.0 Missing Auth Allows Unauthorized AccessMissing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0. |
|
| CVE-2024-10484 | Dec 03, 2024 |
Stored XSS Vulnerability in Spectra WordPress Gutenberg Blocks PluginThe Spectra WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2024-10325 | Nov 08, 2024 |
Elementor Header & Footer XSS via SVG UploadThe Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. |
|
| CVE-2024-37517 | Nov 01, 2024 |
Missing Auth in Brainstorm Force Spectra 2.13.7 Access Control VulnerabilityMissing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.13.7. |
|
| CVE-2024-50439 | Oct 28, 2024 |
Brainstorm Force Astra Widgets XSS (1.2.14)Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets astra-widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through <= 1.2.14. |
|
| CVE-2024-10050 | Oct 24, 2024 |
Elementor HFE Shortcode Info Disclosure 1.6.43The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own. |
|
| CVE-2024-47345 | Oct 06, 2024 |
XSS in Brainstorm Force Starter Templates <4.4.0 (Stored)Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from n/a through <= 4.4.0. |
|
| CVE-2024-43151 | Aug 12, 2024 |
Ultimate Addons for Beaver Builder Lite <=1.5.9 XSS StoredImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder Lite allows Stored XSS.This issue affects Ultimate Addons for Beaver Builder Lite: from n/a through 1.5.9. |
|
| CVE-2024-7590 | Aug 12, 2024 |
Brainstorm Force Spectra Stored XSS v2.14.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows DOM-Based XSS.This issue affects Spectra: from n/a through <= 2.14.1. |
|
| CVE-2024-33933 | Jul 22, 2024 |
XSS in Elementor Header, Footer & Blocks Template before 1.6.35Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force, Nikhil Chavan Elementor Header, Footer & Blocks Template allows DOM-Based XSS.This issue affects Elementor Header, Footer & Blocks Template: from n/a through 1.6.35. |
|
| CVE-2024-37278 | Jul 22, 2024 |
CVE-2024-37278 XSS in Cards for Beaver Builder v1.1.4 (Pratik Chaskar)Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pratik Chaskar Cards for Beaver Builder.This issue affects Cards for Beaver Builder: from n/a through 1.1.4. |
|
| CVE-2024-5252 | Jul 17, 2024 |
Ultimate Addons for WPBakery v3.19.20: Stored XSS via ultimate_info_tableThe Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_table shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2024-5254 | Jul 17, 2024 |
Ultimate Addons WPBakery 3.19.20 Stored XSS in ultimate_info_bannerThe Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_banner shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2024-5255 | Jul 17, 2024 |
Stored XSS via ultimate_dual_color in Ultimate Addons WPBakery 3.19.20The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_dual_color shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2024-5253 | Jul 17, 2024 |
XSS in Ultimate Addons for WPBakery upto 3.19.20 via ult_team shortcodeThe Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ult_team shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2024-5251 | Jul 17, 2024 |
Stored XSS in Ultimate Addons for WPBakery <=3.19.20 via ultimate_pricingThe Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_pricing shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|