Brainstormforce Starter Templates
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Brainstormforce Starter Templates.
By the Year
In 2026 there have been 0 vulnerabilities in Brainstormforce Starter Templates. Last year, in 2025 Starter Templates had 2 security vulnerabilities published. Right now, Starter Templates is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 2 | 6.55 |
| 2024 | 5 | 5.78 |
| 2023 | 2 | 4.85 |
| 2022 | 0 | 0.00 |
| 2021 | 1 | 5.40 |
It may take a day or so for new Starter Templates vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Brainstormforce Starter Templates Security Vulnerabilities
WordPress Starter Templates <4.4.41 AFU via WXR double-ext
CVE-2025-13065
8.8 - High
- December 06, 2025
The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Unrestricted File Upload
CSRF in Brainstorm Force Starter Templates <=4.4.9
CVE-2025-24568
4.3 - Medium
- January 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates astra-sites allows Cross Site Request Forgery.This issue affects Starter Templates: from n/a through <= 4.4.9.
Session Riding
XSS in Brainstorm Force Starter Templates <4.4.0 (Stored)
CVE-2024-47345
5.9 - Medium
- October 06, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from n/a through <= 4.4.0.
XSS
Missing Auth in Brainstorm Force Starter Templates 3.2.5
CVE-2023-41805
6.5 - Medium
- June 19, 2024
Missing Authorization vulnerability in Brainstorm Force Premium Starter Templates, Brainstorm Force Starter Templates astra-sites.This issue affects Premium Starter Templates: from n/a through 3.2.5; Starter Templates: from n/a through 3.2.5.
AuthZ
Stored XSS in Starter Templates Elementor plugin <=4.2.0 via custom_upload_mimes
CVE-2024-4630
6.4 - Medium
- May 14, 2024
The Starter Templates Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_upload_mimes function in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
SSRF via ai_api_request in Starter Templates plugin <4.1.6
CVE-2024-1467
4.3 - Medium
- May 14, 2024
The Starter Templates Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.6 via the ai_api_request(). This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
SSRF
Brainstorm Force Starter Templates SSRF vuln (3.2.4 and earlier)
CVE-2023-34370
- March 28, 2024
Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates Elementor, WordPress & Beaver Builder Templates, Brainstorm Force Premium Starter Templates.This issue affects Starter Templates Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4; Premium Starter Templates: from n/a through 3.2.4.
SSRF
SSRF in Brainstorm Force Starter Templates <=3.2.4
CVE-2023-41804
5.4 - Medium
- December 07, 2023
Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4.
SSRF
CSRF in Brainstorm Force Starter Templates Plugin <=3.1.20
CVE-2022-46851
4.3 - Medium
- May 23, 2023
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions.
Session Riding
On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability
CVE-2021-42360
5.4 - Medium
- November 17, 2021
On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft and host a block containing malicious JavaScript on a server they controlled, and then use it to overwrite any post or page by sending an AJAX request with the action set to astra-page-elementor-batch-process and the url parameter pointed to their remotely-hosted malicious block, as well as an id parameter containing the post or page to overwrite. Any post or page that had been built with Elementor, including published pages, could be overwritten by the imported block, and the malicious JavaScript in the imported block would then be executed in the browser of any visitors to that page.
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Brainstormforce Starter Templates or by Brainstormforce? Click the Watch button to subscribe.