| CVE-2024-6346 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget | pickplugins | Post Grid | Medium | 6.4 | 2024-08-01 09:29:48 | Deep Dive |
| CVE-2024-7100 | Bold Page Builder <= 5.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_button Shortcode | boldthemes | Bold Page Builder | Medium | 6.4 | 2024-07-30 06:48:47 | Deep Dive |
| CVE-2024-4260 | CoBlocks < 3.1.12 - Contributor+ SSRF | Unknown | Page Builder Gutenberg Blocks | - | - | 2024-07-23 06:00:02 | Deep Dive |
| CVE-2024-37219 | WordPress Page Builder Sandwich plugin <= 5.1.0 - Cross Site Scripting (XSS) vulnerability | PBN Hosting SL | Page Builder Sandwich – Front-End Page Builder | Medium | 6.5 | 2024-07-22 09:23:01 | Deep Dive |
| CVE-2024-6848 | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via File Upload | boldgrid | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor | Medium | 6.4 | 2024-07-20 11:18:28 | Deep Dive |
| CVE-2024-37936 | WordPress Tabs For WPBakery Page Builder plugin <= 1.2 - Cross Site Scripting (XSS) vulnerability | labibahmed | Tabs For WPBakery Page Builder | Medium | 6.5 | 2024-07-20 08:56:02 | Deep Dive |
| CVE-2024-37948 | WordPress Caxton – Create Pro page layouts in Gutenberg plugin <= 1.30.1 - Cross Site Scripting (XSS) vulnerability | PootlePress | Caxton – Create Pro page layouts in Gutenberg | Medium | 6.5 | 2024-07-20 08:29:38 | Deep Dive |
| CVE-2024-3242 | Brizy – Page Builder <= 2.4.44 - Authenticated (Contributor+) Arbitrary File Upload | themefusecom | Brizy – Page Builder | High | 8.8 | 2024-07-18 08:33:04 | Deep Dive |
| CVE-2024-1937 | Brizy – Page Builder <= 2.4.44 - Missing Authorization to Authenticated (Contributor+) Post Modification | themefusecom | Brizy – Page Builder | High | 7.1 | 2024-07-16 08:32:32 | Deep Dive |
| CVE-2024-6465 | WP Links Page <= 4.9.5 - Missing Authorization to Authenticated (Subscriber+) Limited Image Update | rico-macchi | WP Links Page | Medium | 4.3 | 2024-07-13 11:19:02 | Deep Dive |
| CVE-2024-2430 | Website Content in Page or Post < 2024.04.09 - Contributor+ Stored Cross-Site Scripting | Unknown | Website Content in Page or Post | 中危 | - | 2024-07-12 06:00:05 | Deep Dive |
| CVE-2024-6554 | Branda – White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path Disclosure | wpmudev | Branda – White Label & Branding, Free Login Page Customizer | Medium | 5.3 | 2024-07-11 03:33:19 | Deep Dive |
| CVE-2024-4862 | WPBITS Addons For Elementor Page Builder <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets | wpbits | WPBITS Addons For Elementor Page Builder | Medium | 6.4 | 2024-07-09 11:02:41 | Deep Dive |
| CVE-2024-6310 | Advanced AJAX Page Loader <= 2.7.7 - Cross-Site Request Forgery to Arbitrary File Upload | deano1987 | Advanced AJAX Page Loader | High | 8.8 | 2024-07-09 07:38:48 | Deep Dive |
| CVE-2024-4482 | The Plus Addons for Elementor <= 5.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget | posimyththemes | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | Medium | 6.4 | 2024-07-03 07:32:37 | Deep Dive |
| CVE-2024-5419 | Void Contact Form 7 Widget For Elementor Page Builder <= 2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via cf7_redirect_page Attribute | voidthemes | Void Contact Form 7 Widget For Elementor Page Builder | Medium | 6.4 | 2024-07-02 03:14:52 | Deep Dive |
| CVE-2024-5819 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.45 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data Attributes | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-06-29 09:46:43 | Deep Dive |
| CVE-2024-5942 | Page and Post Clone <= 6.0 - Insecure Direct Object Reference to Authenticated (Author+) Sensitive Information Exposure | carlosfazenda | Fast Page & Post Duplicator | Medium | 4.3 | 2024-06-29 04:33:27 | Deep Dive |
| CVE-2024-6296 | Stackable – Page Builder Gutenberg Blocks <= 3.13.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | bfintal | Stackable – Page Builder Gutenberg Blocks | Medium | 6.4 | 2024-06-28 03:36:43 | Deep Dive |
| CVE-2024-4983 | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.0- Authenticated (Contributor+) Stored Cross-Site Scripting | posimyththemes | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | Medium | 6.4 | 2024-06-27 08:34:21 | Deep Dive |