| CVE-2024-32957 | WordPress Page Builder: Live Composer plugin <= 1.5.38 - Broken Access Control vulnerability | Live Composer Team | Page Builder: Live Composer | Medium | 4.7 | 2024-04-26 10:58:36 | Deep Dive |
| CVE-2024-3818 | Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.9 - Authenticated (Contributor+) DOM-Based Cross-Site Scripting via "Social Icons" Block | wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Medium | 5.4 | 2024-04-19 02:34:43 | Deep Dive |
| CVE-2024-32592 | WordPress Void Elementor WHMCS Elements For Elementor Page Builder plugin <= 2.0 - Cross Site Scripting (XSS) vulnerability | VoidCoders, innovs | Void Elementor WHMCS Elements For Elementor Page Builder | Medium | 6.5 | 2024-04-18 08:37:47 | Deep Dive |
| CVE-2024-32593 | WordPress WPBITS Addons For Elementor Page Builder plugin <= 1.3.4.2 - Cross Site Scripting (XSS) vulnerability | WPBits | WPBITS Addons For Elementor Page Builder | Medium | 6.5 | 2024-04-18 08:36:12 | Deep Dive |
| CVE-2024-32517 | WordPress Custom Thank You Page Customize For WooCommerce by Binary Carpenter plugin <= 1.4.12 - Broken Access Control vulnerability | WooCommerce & WordPress Tutorials | Custom Thank You Page Customize For WooCommerce by Binary Carpenter | Medium | 4.3 | 2024-04-17 07:38:38 | Deep Dive |
| CVE-2024-31923 | WordPress Feather Login Page plugin <= 1.1.5 - Cross Site Request Forgery (CSRF) vulnerability | PluginOps | Feather Login Page | Medium | 4.3 | 2024-04-15 09:25:05 | Deep Dive |
| CVE-2024-31933 | WordPress Page Builder: Live Composer plugin <= 1.5.35 - Cross Site Request Forgery (CSRF) vulnerability | Live Composer Team | Page Builder: Live Composer | Medium | 5.4 | 2024-04-15 09:24:07 | Deep Dive |
| CVE-2024-32088 | WordPress Website Builder plugin <= 6.15.20 - Cross Site Request Forgery (CSRF) vulnerability | SeedProd | Coming Soon Page, Under Construction & Maintenance Mode by SeedProd | Medium | 4.3 | 2024-04-15 09:06:53 | Deep Dive |
| CVE-2024-32098 | WordPress Advanced Page Visit Counter plugin <= 8.0.6 - Auth. SQL Injection (SQLi) vulnerability | Page Visit Counter | Advanced Page Visit Counter | High | 7.6 | 2024-04-15 07:39:08 | Deep Dive |
| CVE-2024-31301 | WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Cross Site Request Forgery (CSRF) vulnerability | Themeisle | Multiple Page Generator Plugin – MPG | Medium | 5.4 | 2024-04-12 12:32:01 | Deep Dive |
| CVE-2024-3344 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Author+) Limited File Upload to Stored Cross-Site Scripting | themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | Medium | 6.4 | 2024-04-11 11:03:52 | Deep Dive |
| CVE-2024-3343 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes | themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | Medium | 6.4 | 2024-04-11 11:03:51 | Deep Dive |
| CVE-2024-2735 | Bold Page Builder <= 4.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via "Price List" Element | boldthemes | Bold Page Builder | Medium | 6.4 | 2024-04-10 04:30:20 | Deep Dive |
| CVE-2024-2736 | Bold Page Builder <= 4.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags | boldthemes | Bold Page Builder | Medium | 6.4 | 2024-04-10 04:30:20 | Deep Dive |
| CVE-2024-2734 | Bold Page Builder <= 4.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via AI Features | boldthemes | Bold Page Builder | Medium | 6.4 | 2024-04-10 04:30:19 | Deep Dive |
| CVE-2024-2733 | Bold Page Builder <= 4.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Separator Element | boldthemes | Bold Page Builder | Medium | 5.4 | 2024-04-10 03:31:21 | Deep Dive |
| CVE-2024-3267 | Bold Page Builder <= 4.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_price_list Shortcode | boldthemes | Bold Page Builder | Medium | 6.4 | 2024-04-09 18:59:32 | Deep Dive |
| CVE-2024-2039 | Stackable – Page Builder Gutenberg Blocks <= 3.12.11 - Authenticated(Contributor+) Stored Cross-Site Scripting via Posts Block | bfintal | Stackable – Page Builder Gutenberg Blocks | Medium | 6.4 | 2024-04-09 18:59:27 | Deep Dive |
| CVE-2024-2117 | Elementor Website Builder – More than Just a Page Builder <= 3.20.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Path Widget | elemntor | Elementor Website Builder – more than just a page builder | Medium | 6.4 | 2024-04-09 18:59:21 | Deep Dive |
| CVE-2024-2504 | Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes | softaculous | Page Builder: Pagelayer – Drag and Drop website builder | Medium | 6.4 | 2024-04-09 18:59:21 | Deep Dive |