Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

bplugins — Vulnerabilities & Security Advisories 82

Browse all 82 CVE security advisories affecting bplugins. AI-powered Chinese analysis, POCs, and references for each vulnerability.

bplugins operates as a software development firm specializing in WordPress plugins, primarily focusing on e-commerce solutions and digital product management. Its extensive portfolio has resulted in a significant security footprint, with seventy-two Common Vulnerabilities and Exposures (CVEs) currently documented. Historically, the most prevalent vulnerability classes affecting its products include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from insufficient input validation and improper access controls. These flaws frequently allow unauthenticated attackers to execute arbitrary code or escalate privileges within compromised WordPress installations. While the company generally responds to disclosed issues, the high volume of historical incidents highlights systemic challenges in maintaining rigorous code review processes across its diverse plugin ecosystem. This pattern underscores the critical need for enhanced security testing in widely deployed third-party WordPress extensions to mitigate widespread exploitation risks.

CVE IDTitleCVSSSeverityPublished
CVE-2025-24595 WordPress All Embed – Elementor Addons plugin <= 1.1.3 - Cross Site Scripting (XSS) vulnerability — All Embed – Elementor AddonsCWE-79 6.5 Medium2025-01-24
CVE-2025-22787 WordPress Button Block plugin <= 1.1.5 - Broken Access Control vulnerability — Button BlockCWE-862 4.3 Medium2025-01-15
CVE-2024-13156 HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.35 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via heading Parameter — HTML5 Video Player – Embed and Play Videos in Custom PlayerCWE-79 6.4 Medium2025-01-14
CVE-2025-22815 WordPress Button Block plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerability — Button BlockCWE-79 6.5 Medium2025-01-09
CVE-2024-12560 Button Block – Get fully customizable & multi-functional buttons <= 1.1.5 - Authenticated (Contributor+) Post Disclosure via Post Duplication — Button Block – Design Stylish, Interactive, and Multi-Functional ButtonsCWE-200 4.3 Medium2024-12-19
CVE-2024-11882 FAQ And Answers – Create Frequently Asked Questions Area on WP Sites <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting — Awesome FAQ – Modern Accordion, Tabs,Responsive & Super Fast FAQ Builder.CWE-79 6.4 Medium2024-12-12
CVE-2024-11880 B Testimonial – testimonial plugin for WP <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting — B Testimonial – Customer Testimonials in Custom LayoutsCWE-79 6.4 Medium2024-12-04
CVE-2024-10666 Easy Twitter Feed – Twitter feeds plugin for WP <= 1.2.6 - Authenticated (Contributor+) Post Exposure — Feeds for Twitter – Embed Social Media Posts with Live UpdatesCWE-639 4.3 Medium2024-11-22
CVE-2024-10671 Button Block – Get fully customizable & multi-functional buttons <= 1.1.4 - Authenticated (Contributor+) Post Disclosure — Button Block – Design Stylish, Interactive, and Multi-Functional ButtonsCWE-639 4.3 Medium2024-11-21
CVE-2024-10667 Content Slider Block – Create fully functional slider with Gutenberg block <= 3.1.5 - Authenticated (Contributor+) Post Disclosure — Content Slider Block – Slide Through Text or Media ContentCWE-639 4.3 Medium2024-11-09
CVE-2024-10669 Countdown Timer block – Display the event's date into a timer. <= 1.2.4 - Authenticated (Contributor+) Post Disclosure — Countdown Timer Block – Animated Countdown for Events or LaunchesCWE-639 4.3 Medium2024-11-09
CVE-2024-47631 WordPress Logo Carousel – Clients logo carousel for WP plugin <= 1.2 - Cross Site Scripting (XSS) vulnerability — Logo Carousel – Clients logo carousel for WPCWE-79 6.5 Medium2024-10-05
CVE-2024-7727 HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handler — HTML5 Video Player – Embed and Play Videos in Custom PlayerCWE-862 5.3 Medium2024-09-11
CVE-2024-7721 HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update — HTML5 Video Player – Embed and Play Videos in Custom PlayerCWE-862 4.3 Medium2024-09-11
CVE-2024-43148 WordPress StreamCast <= 2.2.3 - Stored Cross Site Scripting (XSS) vulnerability — StreamCastCWE-79 5.9 Medium2024-08-12
CVE-2024-37445 WordPress HTML5 Audio Player plugin <= 2.2.23 - Cross Site Scripting (XSS) vulnerability — Html5 Audio PlayerCWE-79 6.5 Medium2024-07-22
CVE-2024-4398 HTML5 Audio Player- Best WordPress Audio Player Plugin <= 2.2.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets — HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio PlayerCWE-79 6.4 Medium2024-05-10
CVE-2024-0908 Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page <= 1.13.4 - Missing Authorization to Information Disclosure — Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and FiltersCWE-862 5.3 Medium2024-05-02
CVE-2024-30432 WordPress B Slider plugin <= 1.1.12 - Cross Site Scripting (XSS) vulnerability — B Slider - Slider for your block editorCWE-79 6.5 Medium2024-03-29
CVE-2024-30438 WordPress Print Page block plugin <= 1.0.8 - Cross Site Scripting (XSS) vulnerability — Print Page blockCWE-79 6.5 Medium2024-03-29
CVE-2024-23508 WordPress PDF Poster - PDF Embedder Plugin for WordPress Plugin <= 2.1.17 is vulnerable to Cross Site Scripting (XSS) — PDF Poster – PDF Embedder Plugin for WordPressCWE-79 7.1 High2024-01-31
CVE-2023-5860 Icons Font Loader <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Upload — Icons Font Loader – Load Web Fonts and Icon LibrariesCWE-434 7.2 High2023-11-02

This page lists every published CVE security advisory associated with bplugins. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.