| CVE-2024-12581 | Kadence Blocks <= 3.2.53 - Authenticated (Admin+) Stored Cross-Site Scripting | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 4.4 | 2024-12-13 05:24:49 | Deep Dive |
| CVE-2024-10785 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-11-21 04:24:25 | Deep Dive |
| CVE-2024-9896 | BBP Core – Expand bbPress powered forums with useful features <= 1.2.5 - Reflected Cross-Site Scripting via add_query_arg Parameter | spiderdevs | Forumax – AI Powered Advanced Community Forum Plugin | Medium | 6.1 | 2024-11-02 07:34:03 | Deep Dive |
| CVE-2024-9655 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Widget | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-11-01 07:33:30 | Deep Dive |
| CVE-2024-8486 | Shortcodes and extra features for Phlox theme <= 2.16.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading and Icon Picker Widgets | averta | Shortcodes and extra features for Phlox theme | Medium | 6.4 | 2024-10-05 07:39:01 | Deep Dive |
| CVE-2024-1384 | Premium Portfolio Features for Phlox theme <= 2.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | averta | Premium Portfolio Features for Phlox theme | Medium | 6.4 | 2024-08-29 12:31:10 | Deep Dive |
| CVE-2024-3587 | Premium Portfolio Features for Phlox theme <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via ' Grid Portfolios' | averta | Premium Portfolio Features for Phlox theme | Medium | 6.4 | 2024-07-16 08:32:32 | Deep Dive |
| CVE-2024-5819 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.45 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data Attributes | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-06-29 09:46:43 | Deep Dive |
| CVE-2024-5289 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.42 - Authenticated (Contributor+) Stored Cross-Site Scripting in Google Maps Widget | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-06-27 02:03:03 | Deep Dive |
| CVE-2024-4863 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via titleFont Parameter | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-06-14 08:35:35 | Deep Dive |
| CVE-2024-5222 | Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. <= 3.0.5 - Authenticated (Author+) Stored Cross-Site Scripting | cyberchimps | Responsive Plus – Elementor Templates & Starter Sites | Medium | 6.4 | 2024-06-05 06:50:29 | Deep Dive |
| CVE-2023-37888 | WordPress Phlox Core Elements plugin <= 2.14.0 - Unauthenticated Local File Inclusion vulnerability | By Averta | Shortcodes and extra features for Phlox theme | High | 7.6 | 2024-05-17 06:48:41 | Deep Dive |
| CVE-2024-4208 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typer Effect | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-05-15 02:32:44 | Deep Dive |
| CVE-2024-3189 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 5.4 | 2024-05-15 02:32:43 | Deep Dive |
| CVE-2024-4209 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-05-11 01:56:00 | Deep Dive |
| CVE-2024-4481 | Gutenberg Blocks with AI by Kadence WP <= 3.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Link | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-05-10 06:44:58 | Deep Dive |
| CVE-2023-7064 | Shortcodes and extra features for Phlox theme <= 2.17.5 - Authenticated (Subscriber+) PHP Object Injection via auxin_template_control_importer | averta | Shortcodes and extra features for Phlox theme | High | 7.5 | 2024-05-02 16:52:51 | Deep Dive |
| CVE-2024-2273 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.34 - Authenticated (Contributor+) Stored Cross-Site Scripting | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-05-02 16:52:49 | Deep Dive |
| CVE-2024-3517 | Shortcodes and extra features for Phlox theme <= 2.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Widget | averta | Shortcodes and extra features for Phlox theme | Medium | 6.4 | 2024-05-02 16:52:29 | Deep Dive |
| CVE-2024-1533 | Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | averta | Shortcodes and extra features for Phlox theme | Medium | 6.4 | 2024-05-02 16:52:23 | Deep Dive |