浏览 56+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-39703 | WordPress WPBITS Addons For Elementor Page Builder plugin <= 1.8.1 - Cross Site Scripting (XSS) vulnerability | wpbits | WPBITS Addons For Elementor Page Builder | - | - | 2026-04-08 08:30:47 | Deep Dive |
| CVE-2026-34889 | WordPress Ultimate Addons for WPBakery Page Builder plugin < 3.21.4 - Cross Site Scripting (XSS) vulnerability | Brainstorm Force | Ultimate Addons for WPBakery Page Builder | Medium | 6.5 | 2026-04-01 08:51:32 | Deep Dive |
| CVE-2026-28038 | WordPress Ultimate Addons for WPBakery Page Builder plugin <= 3.21.1 - Broken Access Control vulnerability | Brainstorm_Force | Ultimate Addons for WPBakery Page Builder | Medium | 6.5 | 2026-03-05 05:54:15 | Deep Dive |
| CVE-2025-60087 | WordPress Extensive VC Addons for WPBakery page builder plugin <= 1.9.1 - Local File Inclusion vulnerability | Nenad Obradovic | Extensive VC Addons for WPBakery page builder | - | - | 2026-02-20 15:46:28 | Deep Dive |
| CVE-2025-9082 | WPBITS Addons For Elementor <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting | wpbits | WPBITS Addons For Elementor Page Builder | Medium | 6.4 | 2026-01-28 06:43:44 | Deep Dive |
| CVE-2026-24594 | WordPress Livemesh Addons for WPBakery Page Builder plugin <= 3.9.4 - Cross Site Scripting (XSS) vulnerability | livemesh | Livemesh Addons for WPBakery Page Builder | Medium | 5.9 | 2026-01-23 14:29:02 | Deep Dive |
| CVE-2024-23511 | WordPress The Plus Addons for Elementor plugin <= 5.3.3 - Cross Site Scripting (XSS) vulnerability | POSIMYTH | The Plus Addons for Elementor Page Builder Lite | Medium | 6.5 | 2026-01-05 13:33:58 | Deep Dive |
| CVE-2025-14475 | Extensive VC Addons for WPBakery page builder <= 1.9.1 - Unauthenticated Local File Inclusion via 'shortcode_name' Parameter | nenad-obradovic | Extensive VC Addons for WPBakery page builder | High | 8.1 | 2025-12-13 04:31:25 | Deep Dive |
| CVE-2025-48088 | WordPress Ultimate Addons for WPBakery Page Builder plugin < 3.21.1 - Cross Site Scripting (XSS) vulnerability | Brainstorm_Force | Ultimate Addons for WPBakery Page Builder | Medium | 6.5 | 2025-10-27 02:09:52 | Deep Dive |
| CVE-2025-53463 | WordPress HT Mega – Absolute Addons for WPBakery Page Builder Plugin <= 1.0.9 - Cross Site Scripting (XSS) Vulnerability | HT Plugins | HT Mega – Absolute Addons for WPBakery Page Builder | Medium | 6.5 | 2025-09-22 18:25:36 | Deep Dive |
| CVE-2025-55712 | WordPress The Plus Addons for Elementor Page Builder Lite Plugin <= 6.3.13 - Broken Access Control Vulnerability | POSIMYTH | The Plus Addons for Elementor Page Builder Lite | Medium | 6.5 | 2025-08-14 18:21:26 | Deep Dive |
| CVE-2024-37945 | WordPress WPBITS Addons For Elementor plugin <= 1.5 - Cross Site Scripting (XSS) vulnerability | wpbits | WPBITS Addons For Elementor Page Builder | Medium | 6.5 | 2025-08-14 17:15:51 | Deep Dive |
| CVE-2025-7727 | Gutenverse <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Fun Fact Blocks | jegstudio | Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem | Medium | 6.4 | 2025-08-06 06:38:40 | Deep Dive |
| CVE-2025-53206 | WordPress HT Mega – Absolute Addons for WPBakery Page Builder plugin <= 1.0.8 - Cross Site Scripting (XSS) Vulnerability | HT Plugins | HT Mega – Absolute Addons for WPBakery Page Builder | Medium | 6.5 | 2025-06-27 13:21:02 | Deep Dive |
| CVE-2025-49076 | WordPress The Plus Addons for Elementor Page Builder Lite plugin <= 6.2.7 - Cross Site Scripting (XSS) vulnerability | POSIMYTH | The Plus Addons for Elementor Page Builder Lite | Medium | 6.5 | 2025-06-06 11:36:40 | Deep Dive |
| CVE-2025-2893 | Gutenverse <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via countdown Block | jegstudio | Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem | Medium | 6.4 | 2025-04-29 06:37:47 | Deep Dive |
| CVE-2025-2573 | Amazing service box Addons For WPBakery Page Builder <= 2.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | zia420 | Amazing service box Addons For WPBakery Page Builder (formerly Visual Composer) | Medium | 6.4 | 2025-03-26 02:23:49 | Deep Dive |
| CVE-2024-56285 | WordPress WPBITS Addons For Elementor Page Builder plugin <= 1.5.1 - Cross-Site Scripting vulnerability | wpbits | WPBITS Addons For Elementor Page Builder | Medium | 6.5 | 2025-01-07 10:49:19 | Deep Dive |
| CVE-2024-56286 | WordPress Classic Addons – WPBakery Page Builder plugin <= 3.0 - Local File Inclusion vulnerability | webcodingplace | Classic Addons – WPBakery Page Builder | High | 7.5 | 2025-01-07 10:49:18 | Deep Dive |
| CVE-2025-22316 | WordPress WPBITS Addons For Elementor Page Builder plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability | wpbits | WPBITS Addons For Elementor Page Builder | Medium | 5.9 | 2025-01-07 10:48:53 | Deep Dive |