| CVE-2024-5289 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.42 - Authenticated (Contributor+) Stored Cross-Site Scripting in Google Maps Widget | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-06-27 02:03:03 | Deep Dive |
| CVE-2024-37230 | WordPress Book Landing Page theme <= 1.2.3 - Cross Site Request Forgery (CSRF) vulnerability | Rara Theme | Book Landing Page | Medium | 4.3 | 2024-06-21 13:38:53 | Deep Dive |
| CVE-2024-35768 | WordPress Page Builder: Live Composer plugin <= 2.1.13 - Cross Site Scripting (XSS) vulnerability | LiveComposer | Page Builder: Live Composer | Medium | 5.9 | 2024-06-21 12:27:55 | Deep Dive |
| CVE-2024-35779 | WordPress Page Builder: Live Composer plugin <= 1.5.42 - Contributor+ Shortcode Cross Site Scripting (XSS) vulnerability | Live Composer Team | Page Builder: Live Composer | Medium | 6.5 | 2024-06-21 11:40:07 | Deep Dive |
| CVE-2024-5191 | Branda – White Label WordPress, Custom Login Page Customizer <= 3.4.17 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload | wpmudev | Branda – White Label & Branding, Free Login Page Customizer | Medium | 6.4 | 2024-06-21 06:58:19 | Deep Dive |
| CVE-2024-5455 | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.6 - Authenticated (Contributor+) Local File Inclusion | posimyththemes | The Plus Addons for Elementor Page Builder Pro | High | 8.8 | 2024-06-21 03:24:40 | Deep Dive |
| CVE-2024-5344 | The Plus Addons for Elementor Page Builder <= 5.5.6 - Reflected Cross-Site Scripting via WP Login and Register Widget | posimyththemes | The Plus Addons for Elementor Page Builder Pro | Medium | 6.1 | 2024-06-21 02:05:41 | Deep Dive |
| CVE-2024-3597 | Export WP Page to Static HTML/CSS <= 2.2.2 - Open Redirect | recorp | Export WordPress Pages to Static HTML & PDF — Static Site Export | High | 7.1 | 2024-06-20 02:08:24 | Deep Dive |
| CVE-2024-35765 | WordPress Greenshift – animation and page builder blocks plugin <= 8.8.9.1 - Cross Site Scripting (XSS) vulnerability | Wpsoul | Greenshift – animation and page builder blocks | Medium | 6.5 | 2024-06-19 10:17:56 | Deep Dive |
| CVE-2024-35780 | WordPress Page Builder: Live Composer plugin <= 1.5.42 - Contributor+ PHP Object Injection vulnerability | Live Composer Team | Page Builder: Live Composer | High | 8.5 | 2024-06-19 10:16:07 | Deep Dive |
| CVE-2024-4863 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via titleFont Parameter | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-06-14 08:35:35 | Deep Dive |
| CVE-2024-35709 | WordPress The Plus Addons for Elementor plugin <= 5.5.4 - Cross Site Scripting (XSS) vulnerability | POSIMYTH | The Plus Addons for Elementor Page Builder Lite | Medium | 6.5 | 2024-06-08 14:03:11 | Deep Dive |
| CVE-2024-5087 | Minimal Coming Soon – Coming Soon Page <= 2.38 - Missing Authorization to Limited Settings Change | webfactory | Minimal Coming Soon – Coming Soon Page | Medium | 6.3 | 2024-06-08 05:44:30 | Deep Dive |
| CVE-2024-4703 | One Page Express Companion <= 1.6.37 - Authenticated (Contributor+) Stored Cross-Site Scripting via one_page_express_contact_form Shortcode | horearadu | One Page Express Companion | Medium | 6.4 | 2024-06-07 07:35:28 | Deep Dive |
| CVE-2024-4451 | Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_video_player Shortcode | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-06-07 06:52:22 | Deep Dive |
| CVE-2024-4042 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute | pickplugins | Post Grid | Medium | 6.4 | 2024-06-07 05:33:45 | Deep Dive |
| CVE-2024-1988 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting | pickplugins | Post Grid | Medium | 6.4 | 2024-06-07 03:21:58 | Deep Dive |
| CVE-2024-5038 | Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-06-06 11:03:03 | Deep Dive |
| CVE-2024-4088 | Gutenberg Blocks and Page Layouts – Attire Blocks <= 1.9.2 - Missing Authorization | shafayat-alam | Gutenberg Blocks and Page Layouts – Attire Blocks | Medium | 4.3 | 2024-06-05 06:50:30 | Deep Dive |
| CVE-2024-1164 | Brizy – Page Builder <= 2.4.43 - Authenticated(Contributor+) Stored Cross-Site Scripting via Form Functionality | themefusecom | Brizy – Page Builder | Medium | 6.4 | 2024-06-05 06:50:29 | Deep Dive |