Starter Templates Brainstormforce Starter Templates

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Brainstormforce Starter Templates.

By the Year

In 2026 there have been 0 vulnerabilities in Brainstormforce Starter Templates. Last year, in 2025 Starter Templates had 2 security vulnerabilities published. Right now, Starter Templates is on track to have less security vulnerabilities in 2026 than it did last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 2 6.55
2024 5 5.78
2023 2 4.85
2022 0 0.00
2021 1 5.40

It may take a day or so for new Starter Templates vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Brainstormforce Starter Templates Security Vulnerabilities

WordPress Starter Templates <4.4.41 AFU via WXR double-ext
CVE-2025-13065 8.8 - High - December 06, 2025

The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Unrestricted File Upload

CSRF in Brainstorm Force Starter Templates <=4.4.9
CVE-2025-24568 4.3 - Medium - January 24, 2025

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates astra-sites allows Cross Site Request Forgery.This issue affects Starter Templates: from n/a through <= 4.4.9.

Session Riding

XSS in Brainstorm Force Starter Templates <4.4.0 (Stored)
CVE-2024-47345 5.9 - Medium - October 06, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from n/a through <= 4.4.0.

XSS

Missing Auth in Brainstorm Force Starter Templates 3.2.5
CVE-2023-41805 6.5 - Medium - June 19, 2024

Missing Authorization vulnerability in Brainstorm Force Premium Starter Templates, Brainstorm Force Starter Templates astra-sites.This issue affects Premium Starter Templates: from n/a through 3.2.5; Starter Templates: from n/a through 3.2.5.

AuthZ

Stored XSS in Starter Templates Elementor plugin <=4.2.0 via custom_upload_mimes
CVE-2024-4630 6.4 - Medium - May 14, 2024

The Starter Templates Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_upload_mimes function in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

SSRF via ai_api_request in Starter Templates plugin <4.1.6
CVE-2024-1467 4.3 - Medium - May 14, 2024

The Starter Templates Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.6 via the ai_api_request(). This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

SSRF

Brainstorm Force Starter Templates SSRF vuln (3.2.4 and earlier)
CVE-2023-34370 - March 28, 2024

Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates Elementor, WordPress & Beaver Builder Templates, Brainstorm Force Premium Starter Templates.This issue affects Starter Templates Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4; Premium Starter Templates: from n/a through 3.2.4.

SSRF

SSRF in Brainstorm Force Starter Templates <=3.2.4
CVE-2023-41804 5.4 - Medium - December 07, 2023

Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4.

SSRF

CSRF in Brainstorm Force Starter Templates Plugin <=3.1.20
CVE-2022-46851 4.3 - Medium - May 23, 2023

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions.

Session Riding

On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability
CVE-2021-42360 5.4 - Medium - November 17, 2021

On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft and host a block containing malicious JavaScript on a server they controlled, and then use it to overwrite any post or page by sending an AJAX request with the action set to astra-page-elementor-batch-process and the url parameter pointed to their remotely-hosted malicious block, as well as an id parameter containing the post or page to overwrite. Any post or page that had been built with Elementor, including published pages, could be overwritten by the imported block, and the malicious JavaScript in the imported block would then be executed in the browser of any visitors to that page.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Brainstormforce Starter Templates or by Brainstormforce? Click the Watch button to subscribe.

subscribe