Vulnerabilities > Brainstormforce

DATE CVE VULNERABILITY TITLE RISK
2023-07-01 CVE-2020-36737 Unspecified vulnerability in Brainstormforce Import / Export Customizer Settings 1.0.1/1.0.2/1.0.3
The Import / Export Customizer Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.3.
network
low complexity
brainstormforce
4.3
2023-06-07 CVE-2020-36702 Missing Authorization vulnerability in Brainstormforce Spectra
The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7.
network
low complexity
brainstormforce CWE-862
4.3
2023-05-26 CVE-2023-25058 Cross-Site Request Forgery (CSRF) vulnerability in Brainstormforce Schema
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions.
network
low complexity
brainstormforce CWE-352
8.8
2023-05-23 CVE-2022-46851 Cross-Site Request Forgery (CSRF) vulnerability in Brainstormforce Starter Templates
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions.
network
low complexity
brainstormforce CWE-352
8.8
2023-02-21 CVE-2020-36656 Cross-site Scripting vulnerability in Brainstormforce Spectra
The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.
network
low complexity
brainstormforce CWE-79
5.4
2021-11-17 CVE-2021-42360 Resource Injection vulnerability in Brainstormforce Starter Templates
On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action.
3.5
2021-08-09 CVE-2021-24507 SQL Injection vulnerability in Brainstormforce Astra
The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues
network
low complexity
brainstormforce CWE-89
7.5
2021-05-05 CVE-2021-24271 Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Elementor
The “Ultimate Addons for Elementor” WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
3.5
2021-05-05 CVE-2021-24256 Cross-site Scripting vulnerability in Brainstormforce Elementor - Header, Footer & Blocks Template
The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
3.5
2020-05-17 CVE-2020-13125 Incorrect Permission Assignment for Critical Resource vulnerability in Brainstormforce Ultimate Addons for Elementor
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126.
network
low complexity
brainstormforce CWE-732
6.4