Vowelweb
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Vowelweb product.
RSS Feeds for Vowelweb security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Vowelweb products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Vowelweb Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 11 vulnerabilities in Vowelweb with an average score of 5.3 out of ten. Last year, in 2025 Vowelweb had 3 security vulnerabilities published. That is, 8 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.04
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 11 | 5.31 |
| 2025 | 3 | 5.35 |
| 2024 | 5 | 6.03 |
| 2023 | 1 | 5.40 |
| 2022 | 1 | 3.50 |
It may take a day or so for new Vowelweb vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Vowelweb Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-1984 | Sep 19, 2026 |
Ibtana Ecommerce Addons WP v0.4.7.7: Unauthorized Post Meta via AJAXThe Ibtana Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update or delete arbitrary post meta entries via the 'iepa_builder' meta key. |
|
| CVE-2026-2278 | Sep 19, 2026 |
WordPress VW Writer Blog 1.3.8: Cap Check Missing in Reset SettingsThe VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all theme customizer settings to their defaults. |
|
| CVE-2026-57776 | Jul 13, 2026 |
VW Wedding <=1.3.7 Missing Auth in vw-wedding (Incorrect Access Control)Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Wedding: from n/a through <= 1.3.7. |
|
| CVE-2026-57774 | Jul 13, 2026 |
VW Food Corner <=1.1.0 Missing Auth (vw-food-corner)Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Food Corner: from n/a through <= 1.1.0. |
|
| CVE-2026-1834 | Mar 31, 2026 |
Ibtana WP Builder Plugin <=1.2.5.7 Stored XSS via 'ive' shortcodeThe Ibtana WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ive' shortcode in all versions up to, and including, 1.2.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2026-32436 | Mar 13, 2026 |
VW Photography WP plugin missing auth through 1.3.8Missing Authorization vulnerability in vowelweb VW Photography vw-photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Photography: from n/a through <= 1.3.8. |
|
| CVE-2026-32438 | Mar 13, 2026 |
Missing Auth in VW School Education <=1.4.6 WP PluginMissing Authorization vulnerability in vowelweb VW School Education vw-school-education allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW School Education: from n/a through <= 1.4.6. |
|
| CVE-2026-32437 | Mar 13, 2026 |
Vowelweb VW Portfolio <=1.3.3: vw-portfolio Missing Auth (CVE-2026-32437)Missing Authorization vulnerability in vowelweb VW Portfolio vw-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Portfolio: from n/a through <= 1.3.3. |
|
| CVE-2026-32435 | Mar 13, 2026 |
VW Pet Shop <=1.4.7 Missing Auth via Incorrect AC LevelsMissing Authorization vulnerability in vowelweb VW Pet Shop vw-pet-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Pet Shop: from n/a through <= 1.4.7. |
|
| CVE-2026-32434 | Mar 13, 2026 |
Missing Auth in VW Fitness <=4.3.4 (vowelweb)Missing Authorization vulnerability in vowelweb VW Fitness vw-fitness allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Fitness: from n/a through <= 4.3.4. |
|
| CVE-2026-32427 | Mar 13, 2026 |
Missing Auth in VW Education Lite <=2.2.0 Exploits Access ControlMissing Authorization vulnerability in vowelweb VW Education Lite vw-education-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Education Lite: from n/a through <= 2.2.0. |
|
| CVE-2025-5092 | Nov 20, 2025 |
WordPress Plugins: XSS via lightGallery <=2.8.3 (Contributor+ attacks)Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2025-26955 | Apr 15, 2025 |
VW Themes Industrial Lite <1.0.8 Missing Auth VulnerabilityMissing Authorization vulnerability in vowelweb Industrial Lite industrial-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Industrial Lite: from n/a through <= 1.0.8. |
|
| CVE-2024-13686 | Mar 04, 2025 |
VW Storefront 0.9.9: Auth Users Can Reset Settings (Missing Cap)The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all versions up to, and including, 0.9.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the themes settings. |
|
| CVE-2024-56234 | Dec 31, 2024 |
VW THEMES VW Automobile Lite: Missing Authorization Vulnerability in Access ControlMissing Authorization vulnerability in vowelweb VW Automobile Lite vw-automobile-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Automobile Lite: from n/a through <= 2.1. |
|
| CVE-2024-37123 | Nov 01, 2024 |
Missing Auth Vulnerability in VowelWeb Ibtana (1.2.3.3)Missing Authorization vulnerability in VowelWeb Ibtana allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ibtana: from n/a through 1.2.3.3. |
|
| CVE-2024-8282 | Oct 02, 2024 |
Ibtana WP Builder 1.2.4.4: Stored XSS via align attr in Gutenberg blockThe Ibtana WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the align attribute within the 'wp:ive/ive-productscarousel' Gutenberg block in all versions up to, and including, 1.2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2024-5541 | Jun 18, 2024 |
Ibtana WP Builder 1.2.3.3 Auth Bypass on Option ModificationThe Ibtana WordPress Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ibtana_visual_editor_register_ajax_json_endpont' function in all versions up to, and including, 1.2.3.3. This makes it possible for unauthenticated attackers to update option values for reCAPTCHA keys on the WordPress site. This can be leveraged to bypass reCAPTCHA on the site. CVE-2024-37123 is likely a duplicate of this issue. |
|
| CVE-2023-6684 | Jan 11, 2024 |
Ibtana WP Builder 1.2.2 XSS via 'ive' shortcode attrsThe Ibtana WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' shortcode in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on 'width' and 'height' user supplied attribute. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
|
| CVE-2022-4674 | Feb 06, 2023 |
Stored XSS via unescaped shortcode attribute Ibtana WP plugin <1.1.8.8The Ibtana WordPress plugin before 1.1.8.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack |
|
| CVE-2021-25014 | Feb 14, 2022 |
The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX actionThe Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue. |
|