Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

stellarwp — Vulnerabilities & Security Advisories 134

Browse all 134 CVE security advisories affecting stellarwp. AI-powered Chinese analysis, POCs, and references for each vulnerability.

StellarWP primarily develops and maintains premium WordPress plugins, including the popular MemberPress platform for membership management and subscription billing. Historically, its software has been associated with a significant volume of Common Vulnerabilities and Exposures, totaling 115 recorded instances. These security issues predominantly involve cross-site scripting (XSS), SQL injection, and arbitrary file upload flaws, often stemming from insufficient input validation and weak access controls within plugin code. While the company generally responds to disclosed vulnerabilities, the high frequency of patches indicates persistent challenges in secure coding practices. Notable incidents include multiple remote code execution (RCE) vectors that allowed attackers to compromise WordPress installations without authentication. The sheer number of CVEs suggests that while the products are widely used, their security posture has frequently lagged behind industry standards, requiring users to prioritize timely updates and rigorous security auditing to mitigate risks associated with these historically common vulnerability classes.

CVE ID Title CVSS Severity Published
CVE-2025-5144 The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting — The Events Calendar CWE-79 6.4 Medium 2025-06-11
CVE-2025-48246 WordPress The Events Calendar plugin <= 6.11.2.1 - Broken Access Control Vulnerability — The Events Calendar CWE-862 5.4 Medium 2025-05-19
CVE-2025-39557 WordPress Kadence WooCommerce Email Designer plugin <= 1.5.14 - Arbitrary File Upload vulnerability — Kadence WooCommerce Email Designer CWE-434 9.1 Critical 2025-04-16
CVE-2025-30794 WordPress Event Tickets plugin <= 5.20.0 - Reflected Cross Site Scripting (XSS) vulnerability — Event Tickets CWE-79 7.1 High 2025-04-01
CVE-2025-2331 GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure — GiveWP – Donation Plugin and Fundraising Platform CWE-200 5.3 Medium 2025-03-22
CVE-2025-2025 Give <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function — GiveWP – Donation Plugin and Fundraising Platform CWE-862 6.5 Medium 2025-03-15
CVE-2025-0912 GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection — GiveWP – Donation Plugin and Fundraising Platform CWE-502 9.8 Critical 2025-03-04
CVE-2025-1291 Gutenberg Blocks by Kadence Blocks <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor CWE-79 6.4 Medium 2025-03-01
CVE-2025-22633 WordPress Give – Divi Donation Modules plugin <= 2.0.0 - Sensitive Data Exposure vulnerability — Give – Divi Donation Modules CWE-538 5.8 Medium 2025-02-23
CVE-2025-1402 Event Tickets and Registration <= 5.19.1.1 - Missing Authorization to Ticket Deletion — Event Tickets and Registration CWE-862 5.3 Medium 2025-02-21
CVE-2024-13457 Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposure — Event Tickets and Registration CWE-284 5.3 Medium 2025-01-30
CVE-2025-24537 WordPress The Events Calendar plugin <= 6.7.0 - Cross Site Request Forgery (CSRF) vulnerability — The Events Calendar CWE-352 5.4 Medium 2025-01-27
CVE-2024-11090 Membership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Membership Plugin – Restrict Content CWE-200 5.3 Medium 2025-01-26
CVE-2025-24753 WordPress Kadence Blocks plugin <= 3.3.1 - Broken Access Control vulnerability — Gutenberg Blocks by Kadence Blocks CWE-862 4.3 Medium 2025-01-24
CVE-2024-12118 The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting — The Events Calendar CWE-79 6.4 Medium 2025-01-23
CVE-2025-22777 WordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerability — GiveWP CWE-502 9.8 Critical 2025-01-13
CVE-2024-12877 GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection — GiveWP – Donation Plugin and Fundraising Platform CWE-502 9.8 Critical 2025-01-11
CVE-2024-12304 Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor CWE-79 6.4 Medium 2025-01-11
CVE-2024-38762 WordPress Event Tickets and Registration plugin <= 5.11.0.4 - Cross Site Request Forgery (CSRF) vulnerability — Event Tickets CWE-352 4.3 Medium 2025-01-02
CVE-2024-37518 WordPress The Events Calendar plugin <= 6.5.1.4 - Cross Site Request Forgery (CSRF) vulnerability — The Events Calendar CWE-352 4.3 Medium 2025-01-02
CVE-2023-47183 WordPress GiveWP plugin <= 2.33.1 - Broken Access Control vulnerability — GiveWP CWE-862 5.3 Medium 2025-01-02
CVE-2024-12581 Kadence Blocks <= 3.2.53 - Authenticated (Admin+) Stored Cross-Site Scripting — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor CWE-79 4.4 Medium 2024-12-13
CVE-2024-10785 Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor CWE-79 6.4 Medium 2024-11-21
CVE-2024-9655 Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Widget — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor CWE-79 6.4 Medium 2024-11-01
CVE-2024-9634 GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution — GiveWP – Donation Plugin and Fundraising Platform CWE-502 9.8 Critical 2024-10-16
CVE-2024-8353 GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection — GiveWP – Donation Plugin and Fundraising Platform CWE-502 9.8 Critical 2024-09-28
CVE-2024-6931 The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting — The Events Calendar CWE-79 7.2 High 2024-09-27
CVE-2024-9130 GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Authenticated (GiveWP Manager+) SQL Injection via order Parameter — GiveWP – Donation Plugin and Fundraising Platform CWE-89 7.2 High 2024-09-27
CVE-2024-47315 WordPress GiveWP – Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) vulnerability — GiveWP CWE-352 5.4 Medium 2024-09-25
CVE-2024-8275 The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection — The Events Calendar CWE-89 9.8 Critical 2024-09-25

This page lists every published CVE security advisory associated with stellarwp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.