Skip to main content

Vendor/product archive

themeum / wp_page_builder CVEs

Beta · best-effort

4 CVEs tagged to themeum / wp_page_builder0 Critical, 0 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2022-3830

Published Dec 5, 2022

The WP Page Builder WordPress plugin through 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-40963

Published Nov 18, 2022

Multiple Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerabilities in WP Page Builder plugin <= 1.2.6 on WordPress.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24208

Published Apr 5, 2021

The editor of the WP Page Builder WordPress plugin before 1.2.4 allows lower-privileged users to insert unfiltered HTML, including JavaScript, into pages via the “Raw HTML” widget…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-24207

Published Apr 5, 2021

By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to any and all posts pages - user roles must be specifically b…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1