Skip to content
Noroxi

wpbeginner records

5 published records for vendor wpbeginner.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
20%
Median publish → KEV
No record has entered KEV

Records by year

  1. 24
  2. 25

Bar: total · dark part: CISA KEV.

Attack profile

All records

5 records
  • Sugar Calendar (Lite) <= 3.3.0 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    wpbeginner · sugar calendarNov 26, 2024

  • CVE-2025-4577
    21Monitor

    Smash Balloon Custom Facebook Feed <= 4.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-color` Attribute

    MediumCVSS 5.4No exploitEPSS 0%

    wpbeginner · smash balloon social post feedJun 10, 2025

  • CVE-2015-5528
    18Monitor

    Cross-site scripting (XSS) vulnerability in the save_order function in class-floating-social-bar.php in the Floating Social Bar plugin befor

    MediumCVSS 4.3No exploitEPSS 2%

    wpbeginner · floating social barJul 16, 2015

  • Transients Manager <= 2.0.6 - Cross-Site Request Forgery

    MediumCVSS 4.3No exploitEPSS 0%

    wpbeginner · transients managerOct 23, 2024

  • CVE-2025-5275
    16Monitor

    Charitable <= 1.8.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin's Privacy Settings

    MediumCVSS 4.0No exploitEPSS 0%

    wpbeginner · charitableJun 25, 2025