Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

stellarwp — Vulnerabilities & Security Advisories 134

Browse all 134 CVE security advisories affecting stellarwp. AI-powered Chinese analysis, POCs, and references for each vulnerability.

StellarWP primarily develops and maintains premium WordPress plugins, including the popular MemberPress platform for membership management and subscription billing. Historically, its software has been associated with a significant volume of Common Vulnerabilities and Exposures, totaling 115 recorded instances. These security issues predominantly involve cross-site scripting (XSS), SQL injection, and arbitrary file upload flaws, often stemming from insufficient input validation and weak access controls within plugin code. While the company generally responds to disclosed vulnerabilities, the high frequency of patches indicates persistent challenges in secure coding practices. Notable incidents include multiple remote code execution (RCE) vectors that allowed attackers to compromise WordPress installations without authentication. The sheer number of CVEs suggests that while the products are widely used, their security posture has frequently lagged behind industry standards, requiring users to prioritize timely updates and rigorous security auditing to mitigate risks associated with these historically common vulnerability classes.

CVE ID Title CVSS Severity Published
CVE-2026-97634 Event Tickets and Registration <= 5.29.5 - Authenticated (Contributor+) SQL Injection via 'orderby' Parameter — Event Tickets and Registration CWE-89 6.5 Medium 2026-10-02
CVE-2026-77820 WPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode Attribute — WPComplete CWE-79 6.4 Medium 2026-09-19
CVE-2026-78159 The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation — The Events Calendar CWE-94 9.8 Critical 2026-09-12
CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution — The Events Calendar CWE-502 9.8 Critical 2026-09-12
CVE-2026-3174 Event Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials Update — Event Tickets and Registration CWE-862 7.5 High 2026-09-08
CVE-2026-12843 LearnDash LMS 4.25.0 - 5.1.6 - Unauthenticated Arbitrary Course Enrollment via REST Endpoint — LearnDash LMS CWE-862 5.4 Medium 2026-09-05
CVE-2026-12483 LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler — LearnDash LMS CWE-434 7.5 High 2026-09-04
CVE-2026-5510 GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes — GiveWP – Donation Plugin and Fundraising Platform CWE-79 6.4 Medium 2026-08-28
CVE-2026-9273 Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover — Membership Plugin – Kadence Memberships CWE-640 9.3 Critical 2026-08-05
CVE-2026-18062 Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor CWE-79 6.4 Medium 2026-08-01
CVE-2026-18435 Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor CWE-79 6.4 Medium 2026-08-01
CVE-2026-14987 GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting — GiveWP – Donation Plugin and Fundraising Platform CWE-79 6.4 Medium 2026-07-16
CVE-2026-15286 Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor CWE-863 4.3 Medium 2026-07-10
CVE-2026-13704 GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form — GiveWP – Donation Plugin and Fundraising Platform CWE-79 6.4 Medium 2026-07-02
CVE-2026-11981 GiveWP <= 4.15.3 - Cross-Site Request Forgery — GiveWP – Donation Plugin and Fundraising Platform CWE-352 4.3 Medium 2026-07-01
CVE-2026-12902 Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor CWE-862 4.3 Medium 2026-07-01
CVE-2026-12904 Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor CWE-639 4.3 Medium 2026-07-01
CVE-2026-13246 GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute — GiveWP – Donation Plugin and Fundraising Platform CWE-79 6.4 Medium 2026-07-01
CVE-2026-11357 Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor CWE-200 4.3 Medium 2026-06-18
CVE-2026-42643 WordPress Image Widget plugin <= 4.4.11 - Cross Site Scripting (XSS) vulnerability — Image Widget CWE-79 5.9 Medium 2026-04-29
CVE-2026-42642 WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerability — GiveWP CWE-862 5.3 Medium 2026-04-29
CVE-2026-2826 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media Upload — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor CWE-862 4.3 Medium 2026-04-04
CVE-2026-32546 WordPress Restrict Content plugin <= 3.2.22 - Broken Access Control vulnerability — Restrict Content CWE-862 7.5 High 2026-03-25
CVE-2026-3079 LearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter — LearnDash LMS CWE-89 6.5 Medium 2026-03-24
CVE-2026-4136 Membership Plugin – Restrict Content <= 3.2.24 - Unvalidated Redirect in Password Reset Flow via rcp_redirect — Membership Plugin – Restrict Content CWE-640 4.3 Medium 2026-03-20
CVE-2026-3585 The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import — The Events Calendar CWE-22 7.5 High 2026-03-10
CVE-2026-1321 Membership Plugin – Restrict Content <= 3.2.20 - Unauthenticated Privilege Escalation via 'rcp_level' — Membership Plugin – Restrict Content CWE-862 8.1 High 2026-03-05
CVE-2026-2694 The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API — The Events Calendar CWE-285 5.4 Medium 2026-02-25
CVE-2026-27056 WordPress iThemes Sync plugin <= 3.2.8 - Broken Access Control vulnerability — iThemes Sync CWE-862 4.3 Medium 2026-02-19
CVE-2026-2633 Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor CWE-862 4.3 Medium 2026-02-18

This page lists every published CVE security advisory associated with stellarwp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.