vciy

CVEs we hold for Stellarwp

Records whose assigning authority named Stellarwp as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9273Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeoverstellarwp Membership Plugin – Kadence Memberships
CVE-2026-78159The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map…stellarwp The Events Calendar
CVE-2026-78006The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Executionstellarwp The Events Calendar
CVE-2026-77820WPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode Attributestellarwp WPComplete
CVE-2026-5510GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributesstellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2026-42643WordPress Image Widget plugin <= 4.4.11 - Cross Site Scripting (XSS) vulnerabilityStellarWP Image Widget
CVE-2026-42642WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerabilityStellarWP GiveWP
CVE-2026-4136Membership Plugin – Restrict Content <= 3.2.24 - Unvalidated Redirect in Password Reset Flow via rcp_redirectstellarwp Membership Plugin – Restrict Content
CVE-2026-3585The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_importstellarwp The Events Calendar
CVE-2026-32546WordPress Restrict Content plugin <= 3.2.22 - Broken Access Control vulnerabilityStellarWP Restrict Content
CVE-2026-3174Event Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials Updatestellarwp Event Tickets and Registration
CVE-2026-3079LearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' ParameterStellarWP LearnDash LMS
CVE-2026-2826Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2026-27056WordPress iThemes Sync plugin <= 3.2.8 - Broken Access Control vulnerabilityStellarWP iThemes Sync
CVE-2026-2694The Events Calendar <= 6.15.16 - Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue…stellarwp The Events Calendar
CVE-2026-2633Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Missing Authorization to Authenticated (Contributor+) Unauthorized…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2026-2608Gutenberg Blocks by Kadence Blocks <= 3.5.32 - Missing Authorizationstellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2026-1857Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery via…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2026-18435Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attributestellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2026-18062Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2026-15286Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2026-14987GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template…stellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2026-13704GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Formstellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2026-13246GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attributestellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2026-1321Membership Plugin – Restrict Content <= 3.2.20 - Unauthenticated Privilege Escalation via 'rcp_level'stellarwp Membership Plugin – Restrict Content
CVE-2026-1304Membership Plugin – Restrict Content <= 3.2.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Invoice…stellarwp Membership Plugin – Restrict Content
CVE-2026-12904Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2026-12902Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2026-12843LearnDash LMS 4.25.0 - 5.1.6 - Unauthenticated Arbitrary Course Enrollment via REST EndpointStellarWP LearnDash LMS
CVE-2026-12483LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload HandlerStellarWP LearnDash LMS
CVE-2026-11981GiveWP <= 4.15.3 - Cross-Site Request Forgerystellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2026-11357Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2025-9808The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosurestellarwp The Events Calendar
CVE-2025-9807The Events Calendar <= 6.15.1 - Unauthenticated SQL Injectionstellarwp The Events Calendar
CVE-2025-8620GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposurestellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2025-7221GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Updatestellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2025-7205GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scriptingstellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2025-69352WordPress The Events Calendar plugin <= 6.15.12.2 - Broken Access Control vulnerabilityStellarWP The Events Calendar
CVE-2025-67467WordPress GiveWP plugin <= 4.13.1 - Cross Site Request Forgery (CSRF) vulnerabilityStellarWP GiveWP
CVE-2025-66533WordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerabilityStellarWP GiveWP
CVE-2025-62027WordPress Event Tickets plugin <= 5.26.3 - Broken Access Control vulnerabilityStellarWP Event Tickets
CVE-2025-58974WordPress WPComplete Plugin <= 2.9.5.2 - Cross Site Scripting (XSS) VulnerabilityStellarWP WPComplete
CVE-2025-5678Kadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2025-54697WordPress Kadence WooCommerce Email Designer Plugin <= 1.5.16 - Privilege Escalation VulnerabilityStellarWP Kadence WooCommerce Email Designer
CVE-2025-5144The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scriptingstellarwp The Events Calendar
CVE-2025-50046WordPress WPComplete plugin <= 2.9.5 - Cross Site Scripting (XSS) VulnerabilityStellarWP WPComplete
CVE-2025-49906WordPress WPComplete plugin <= 2.9.5.3 - Broken Access Control vulnerabilityStellarWP WPComplete
CVE-2025-48246WordPress The Events Calendar plugin <= 6.11.2.1 - Broken Access Control VulnerabilityStellarWP The Events Calendar
CVE-2025-4571GiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+)…stellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2025-39557WordPress Kadence WooCommerce Email Designer plugin <= 1.5.14 - Arbitrary File Upload vulnerabilityStellarWP Kadence WooCommerce Email Designer
CVE-2025-30794WordPress Event Tickets plugin <= 5.20.0 - Reflected Cross Site Scripting (XSS) vulnerabilityStellarWP Event Tickets
CVE-2025-24753WordPress Kadence Blocks plugin <= 3.3.1 - Broken Access Control vulnerabilityStellarWP Gutenberg Blocks by Kadence Blocks
CVE-2025-24537WordPress The Events Calendar plugin <= 6.7.0 - Cross Site Request Forgery (CSRF) vulnerabilityStellarWP The Events Calendar
CVE-2025-2331GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposurestellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2025-22777WordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerabilityStellarWP GiveWP
CVE-2025-22633WordPress Give – Divi Donation Modules plugin <= 2.0.0 - Sensitive Data Exposure vulnerabilityStellarWP Give – Divi Donation Modules
CVE-2025-2025Give <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via…stellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2025-15043The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migration Controlstellarwp The Events Calendar
CVE-2025-14844Membership Plugin – Restrict Content <= 3.2.16 - Missing Authentication to Insecure Direct Object Reference and…stellarwp Membership Plugin – Restrict Content
CVE-2025-1402Event Tickets and Registration <= 5.19.1.1 - Missing Authorization to Ticket Deletionstellarwp Event Tickets and Registration
CVE-2025-14000Membership Plugin – Restrict Content <= 3.2.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodesstellarwp Membership Plugin – Restrict Content
CVE-2025-13387Kadence WooCommerce Email Designer <= 1.5.17 - Unauthenticated Stored Cross-Site Scriptingstellarwp Kadence WooCommerce Email Designer
CVE-2025-13206GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'stellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2025-1291Gutenberg Blocks by Kadence Blocks <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon'stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2025-12633Booking Calendar | Appointment Booking | Bookit <= 2.5.0 - Missing Authorization to Unauthenticated Stripe Connectionstellarwp Bookit — Booking & Appointment Calendar
CVE-2025-12197The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via sstellarwp The Events Calendar
CVE-2025-12192The Events Calendar <= 6.15.9 - Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposurestellarwp The Events Calendar
CVE-2025-12175The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposurestellarwp The Events Calendar
CVE-2025-11517Event Tickets and Registration <= 5.26.5 - Unauthenticated Ticket Payment Bypassstellarwp Event Tickets and Registration
CVE-2025-11228GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign…stellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2025-11227GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and…stellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2025-0912GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injectionstellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-9655Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.1 - Authenticated (Contributor+) Stored…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-9634GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code…stellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-9130GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Authenticated (GiveWP Manager+) SQL Injection via order…stellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-8353GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injectionstellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-8275The Events Calendar <= 6.6.4 - Unauthenticated SQL Injectionstellarwp The Events Calendar
CVE-2024-6931The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scriptingstellarwp The Events Calendar
CVE-2024-6551GiveWP <= 3.15.1 - Unauthenticated Full Path Disclosurestellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-5977GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP…stellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-5941GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Missing Authorization to Authenticated (Subscriber+)…stellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-5940GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings…stellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-5939GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information Exposurestellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-5932GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code…stellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-5819Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.45 - Authenticated (Contributor+) Stored…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-5648LearnDash LMS - Reports Free <= 1.8.2.1 - Missing Authorization to Plugin Settings Updatestellarwp LearnDash LMS – Reports
CVE-2024-5289Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.42 - Authenticated (Contributor+) Stored…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-4863Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.38 - Authenticated (Contributor+) Stored Cross-Site…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-47315WordPress GiveWP – Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF)…StellarWP GiveWP
CVE-2024-4481Gutenberg Blocks with AI by Kadence WP <= 3.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-4209Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.36 - Authenticated (Contributor+) Stored Cross-Site…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-4208Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-4034Virtue <= 3.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Authorstellarwp Virtue
CVE-2024-38762WordPress Event Tickets and Registration plugin <= 5.11.0.4 - Cross Site Request Forgery (CSRF) vulnerabilityStellarWP Event Tickets
CVE-2024-37518WordPress The Events Calendar plugin <= 6.5.1.4 - Cross Site Request Forgery (CSRF) vulnerabilityStellarWP The Events Calendar
CVE-2024-3714GiveWP – Donation Plugin and Fundraising Platform <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scriptingstellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-35679WordPress GiveWP plugin <= 3.12.0 - Reflected Cross Site Scripting (XSS) vulnerabilityStellarWP GiveWP
CVE-2024-3189Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-31433WordPress The Events Calendar plugin <= 6.3.0 - Cross Site Request Forgery (CSRF) vulnerabilityStellarWP The Events Calendar
CVE-2024-31432WordPress Restrict Content plugin <= 3.2.8 - Broken Access Control vulnerabilityStellarWP Restrict Content
CVE-2024-30229WordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerabilityStellarWP GiveWP
CVE-2024-2919Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.31 - Authenticated (Contributor+) DOM-Based Stored…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-27987WordPress Give plugin <= 3.3.1 - Reflected Cross Site Scripting (XSS) vulnerabilityStellarWP GiveWP
CVE-2024-24888WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.2.25 - Server Side Request Forgery (SSRF) vulnerabilityStellarWP Gutenberg Blocks by Kadence Blocks
CVE-2024-23500WordPress Kadence Blocks plugin <= 3.2.19 - Server Side Request Forgery (SSRF) vulnerabilityStellarWP Gutenberg Blocks by Kadence Blocks
CVE-2024-2273Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.34 - Authenticated (Contributor+) Stored Cross-Site…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-2261Event Tickets and Registration <= 5.8.2 - Improper Authorization to Information Disclosurestellarwp Event Tickets and Registration
CVE-2024-1999Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.25 - Authenticated (Contributor+) Stored Cross-Site…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-1957GiveWP – Donation Plugin and Fundraising Platform <= 3.6.1 -- Authenticated(Contributor+) Stored Cross-Site Scripting…stellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-1541Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.23 - Authenticated (Contributor+) Stored Cross-Site…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-1424GiveWP – Donation Plugin and Fundraising Platform <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scriptingstellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-13457Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposurestellarwp Event Tickets and Registration
CVE-2024-12877GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injectionstellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2024-12581Kadence Blocks <= 3.2.53 - Authenticated (Admin+) Stored Cross-Site Scriptingstellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-12304Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-12118The Events Calendar <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scriptingstellarwp The Events Calendar
CVE-2024-1210LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via APIStellarWP LearnDash LMS
CVE-2024-1209LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignmentsStellarWP LearnDash LMS
CVE-2024-1208LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via APIStellarWP LearnDash LMS
CVE-2024-11090Membership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information…stellarwp Membership Plugin – Restrict Content
CVE-2024-10785Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2024-1053Event Tickets and Registration <= 5.8.1 - Missing Authorizationstellarwp Event Tickets and Registration
CVE-2024-0598Gutenberg Blocks by Kadence Blocks <= 3.2.17 - Authenticated(Editor+) Stored Cross-Site Scripting via Contact Form…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2023-6964Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request…stellarwp Kadence Blocks — Page Builder Toolkit for…
CVE-2023-6557The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposurestellarwp The Events Calendar
CVE-2023-47668WordPress Restrict Content Plugin <= 3.2.7 is vulnerable to Sensitive Data ExposureStellarWP Membership Plugin – Restrict Content
CVE-2023-47183WordPress GiveWP plugin <= 2.33.1 - Broken Access Control vulnerabilityStellarWP GiveWP
CVE-2023-4248GiveWP <= 2.33.3 - Cross-Site Request Forgery to Stripe Integration Deletionstellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2023-4247GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin deactivationstellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2023-4246GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin installationstellarwp GiveWP – Donation Plugin and Fundraising Platform
CVE-2023-3105LearnDash LMS <= 4.6.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password ChangeStellarWP LearnDash LMS
CVE-2023-2834BookIt <= 2.3.7 - Authentication Bypassstellarwp Bookit — Booking & Appointment Calendar
CVE-2022-2117GiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 - Sensitive Information Disclosurestellarwp GiveWP – Donation Plugin and Fundraising Platform

133 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.