Vowelweb Vowelweb

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Vowelweb product.

RSS Feeds for Vowelweb security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Vowelweb products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Vowelweb Sorted by Most Security Vulnerabilities since 2018

Vowelweb Ibtana7 vulnerabilities

Vowelweb Industrial Lite1 vulnerability

Vowelweb Vw Fitness1 vulnerability

Vowelweb Vw Food Corner1 vulnerability

Vowelweb Vw Pet Shop1 vulnerability

Vowelweb Vw Photography1 vulnerability

Vowelweb Vw Portfolio1 vulnerability

Vowelweb Vw Wedding1 vulnerability

By the Year

In 2026 there have been 11 vulnerabilities in Vowelweb with an average score of 5.3 out of ten. Last year, in 2025 Vowelweb had 3 security vulnerabilities published. That is, 8 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.04




Year Vulnerabilities Average Score
2026 11 5.31
2025 3 5.35
2024 5 6.03
2023 1 5.40
2022 1 3.50

It may take a day or so for new Vowelweb vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Vowelweb Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-1984 Sep 19, 2026
Ibtana Ecommerce Addons WP v0.4.7.7: Unauthorized Post Meta via AJAX The Ibtana Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update or delete arbitrary post meta entries via the 'iepa_builder' meta key.
Ibtana
CVE-2026-2278 Sep 19, 2026
WordPress VW Writer Blog 1.3.8: Cap Check Missing in Reset Settings The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all theme customizer settings to their defaults.
CVE-2026-57776 Jul 13, 2026
VW Wedding <=1.3.7 Missing Auth in vw-wedding (Incorrect Access Control) Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Wedding: from n/a through <= 1.3.7.
Vw Wedding
CVE-2026-57774 Jul 13, 2026
VW Food Corner <=1.1.0 Missing Auth (vw-food-corner) Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Food Corner: from n/a through <= 1.1.0.
Vw Food Corner
CVE-2026-1834 Mar 31, 2026
Ibtana WP Builder Plugin <=1.2.5.7 Stored XSS via 'ive' shortcode The Ibtana WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ive' shortcode in all versions up to, and including, 1.2.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-32436 Mar 13, 2026
VW Photography WP plugin missing auth through 1.3.8 Missing Authorization vulnerability in vowelweb VW Photography vw-photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Photography: from n/a through <= 1.3.8.
Vw Photography
CVE-2026-32438 Mar 13, 2026
Missing Auth in VW School Education <=1.4.6 WP Plugin Missing Authorization vulnerability in vowelweb VW School Education vw-school-education allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW School Education: from n/a through <= 1.4.6.
Vw School Education
CVE-2026-32437 Mar 13, 2026
Vowelweb VW Portfolio <=1.3.3: vw-portfolio Missing Auth (CVE-2026-32437) Missing Authorization vulnerability in vowelweb VW Portfolio vw-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Portfolio: from n/a through <= 1.3.3.
Vw Portfolio
CVE-2026-32435 Mar 13, 2026
VW Pet Shop <=1.4.7 Missing Auth via Incorrect AC Levels Missing Authorization vulnerability in vowelweb VW Pet Shop vw-pet-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Pet Shop: from n/a through <= 1.4.7.
Vw Pet Shop
CVE-2026-32434 Mar 13, 2026
Missing Auth in VW Fitness <=4.3.4 (vowelweb) Missing Authorization vulnerability in vowelweb VW Fitness vw-fitness allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Fitness: from n/a through <= 4.3.4.
Vw Fitness
CVE-2026-32427 Mar 13, 2026
Missing Auth in VW Education Lite <=2.2.0 Exploits Access Control Missing Authorization vulnerability in vowelweb VW Education Lite vw-education-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Education Lite: from n/a through <= 2.2.0.
Vw Education Lite
CVE-2025-5092 Nov 20, 2025
WordPress Plugins: XSS via lightGallery <=2.8.3 (Contributor+ attacks) Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2025-26955 Apr 15, 2025
VW Themes Industrial Lite <1.0.8 Missing Auth Vulnerability Missing Authorization vulnerability in vowelweb Industrial Lite industrial-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Industrial Lite: from n/a through <= 1.0.8.
Industrial Lite
CVE-2024-13686 Mar 04, 2025
VW Storefront 0.9.9: Auth Users Can Reset Settings (Missing Cap) The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all versions up to, and including, 0.9.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the themes settings.
CVE-2024-56234 Dec 31, 2024
VW THEMES VW Automobile Lite: Missing Authorization Vulnerability in Access Control Missing Authorization vulnerability in vowelweb VW Automobile Lite vw-automobile-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Automobile Lite: from n/a through <= 2.1.
Vw Automobile Lite
CVE-2024-37123 Nov 01, 2024
Missing Auth Vulnerability in VowelWeb Ibtana (1.2.3.3) Missing Authorization vulnerability in VowelWeb Ibtana allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ibtana: from n/a through 1.2.3.3.
Ibtana
CVE-2024-8282 Oct 02, 2024
Ibtana WP Builder 1.2.4.4: Stored XSS via align attr in Gutenberg block The Ibtana WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the align attribute within the 'wp:ive/ive-productscarousel' Gutenberg block in all versions up to, and including, 1.2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Ibtana
CVE-2024-5541 Jun 18, 2024
Ibtana WP Builder 1.2.3.3 Auth Bypass on Option Modification The Ibtana WordPress Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ibtana_visual_editor_register_ajax_json_endpont' function in all versions up to, and including, 1.2.3.3. This makes it possible for unauthenticated attackers to update option values for reCAPTCHA keys on the WordPress site. This can be leveraged to bypass reCAPTCHA on the site. CVE-2024-37123 is likely a duplicate of this issue.
Ibtana
CVE-2023-6684 Jan 11, 2024
Ibtana WP Builder 1.2.2 XSS via 'ive' shortcode attrs The Ibtana WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' shortcode in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on 'width' and 'height' user supplied attribute. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Ibtana
CVE-2022-4674 Feb 06, 2023
Stored XSS via unescaped shortcode attribute Ibtana WP plugin <1.1.8.8 The Ibtana WordPress plugin before 1.1.8.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack
Ibtana
CVE-2021-25014 Feb 14, 2022
The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue.
Ibtana
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.