wpdevteam
Web & CMS Pluginscommercial
Latest CVEs
The 15 most recently published vulnerabilities affecting wpdevteam.
- CVE-2026-12157BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute6.4
- CVE-2026-7665Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler5.3
- CVE-2026-7796EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' Attribute6.4
- CVE-2026-10586Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery7.2
- CVE-2026-5193Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_user6.5
- CVE-2026-4658Gutenberg Essential Blocks <= 6.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes6.4
- CVE-2026-6393BetterDocs <= 4.3.11 - Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage4.3
- CVE-2026-3875BetterDocs <= 4.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes6.4
- CVE-2026-1512Essential Addons for Elementor <= 6.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget6.4
- CVE-2026-0554NotificationX <= 3.1.11 - Missing Authorization to Authenticated (Contributor+) Analytics Reset4.3
- CVE-2025-15380NotificationX <= 3.2.0 - Unauthenticated DOM-Based Cross-Site Scripting via 'nx-preview'7.2
- CVE-2026-1004Essential Addons for Elementor <= 6.5.5 - Missing Authorization to Unauthenticated Sensitive Information Exposure5.3
- CVE-2026-0831Templately <= 3.4.8 - Unauthenticated Limited Arbitrary JSON File Write5.3
- CVE-2025-14980BetterDocs <= 4.3.3 - Authenticated (Contributor+) Sensitive Information Exposure6.5
- CVE-2025-13977Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4