Stellarwp
73 CVEs tracked since 2024. Since Feb 2024, none of them reached CISA KEV.
Stellarwp CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2024-02 | 5 | 0 |
| 2024-03 | null or fewer | |
| 2024-04 | 10 | 0 |
| 2024-05 | 7 | 0 |
| 2024-06 | 5 | 0 |
| 2024-07 | null or fewer | |
| 2024-08 | 5 | 0 |
| 2024-09 | 5 | 0 |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | 11 | 0 |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | 6 | 0 |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | 6 | 0 |
| 2026-03 | null or fewer | |
| 2026-04 | null or fewer | |
| 2026-05 | null or fewer | |
| 2026-06 | null or fewer | |
| 2026-07 | 7 | 0 |
| 2026-08 | null or fewer | |
| 2026-09 | 6 | 0 |
Products
The products that kept showing up in Stellarwp's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Stellarwp.
- CVE-2026-77820WPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode Attribute6.4
- CVE-2026-78159The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation9.8
- CVE-2026-78006The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution9.8
- CVE-2026-3174Event Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials Update7.5
- CVE-2026-12843LearnDash LMS 4.25.0 - 5.1.6 - Unauthenticated Arbitrary Course Enrollment via REST Endpoint5.4
- CVE-2026-12483LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler7.5
- CVE-2026-5510GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes6.4
- CVE-2026-9273Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover9.3
- CVE-2026-18435Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute6.4
- CVE-2026-18062Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content6.4
- CVE-2026-14987GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting6.4
- CVE-2026-15286Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication4.3
- CVE-2026-13704GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form6.4
- CVE-2026-11981GiveWP <= 4.15.3 - Cross-Site Request Forgery4.3
- CVE-2026-12902Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions4.3
The record
- Peak rank
- #72 in Jan 2025
- Busiest month shown
- Jan 2025, 11 CVEs
- Months with a KEV entry
- 0 since Feb 2024
- Monthly snapshots
- 11 since 2024