CVE Tools

Stellarwp

73 CVEs tracked since 2024. Since Feb 2024, none of them reached CISA KEV.

Stellarwp CVEs per month

Feb 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Stellarwp CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0250
2024-03null or fewer
2024-04100
2024-0570
2024-0650
2024-07null or fewer
2024-0850
2024-0950
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01110
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-1060
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-0260
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06null or fewer
2026-0770
2026-08null or fewer
2026-0960

Products

The products that kept showing up in Stellarwp's monthly top three, with their CVEs summed over those months.

  1. Kadence Blocks — Page Builder Toolkit For Gutenberg Editor185 months
  2. Givewp – Donation Plugin and Fundraising Platform166 months
  3. The Events Calendar95 months
  4. Learndash Lms52 months
  5. Givewp43 months
  6. Event Tickets and Registration33 months
  7. Wpcomplete22 months
  8. Gutenberg Blocks By Kadence Blocks11 month
  9. Ithemes Sync11 month
  10. Membership Plugin – Restrict Content11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Stellarwp.

  1. CVE-2026-77820WPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode Attribute6.4
  2. CVE-2026-78159The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation9.8
  3. CVE-2026-78006The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution9.8
  4. CVE-2026-3174Event Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials Update7.5
  5. CVE-2026-12843LearnDash LMS 4.25.0 - 5.1.6 - Unauthenticated Arbitrary Course Enrollment via REST Endpoint5.4
  6. CVE-2026-12483LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler7.5
  7. CVE-2026-5510GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes6.4
  8. CVE-2026-9273Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover9.3
  9. CVE-2026-18435Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute6.4
  10. CVE-2026-18062Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content6.4
  11. CVE-2026-14987GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting6.4
  12. CVE-2026-15286Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication4.3
  13. CVE-2026-13704GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form6.4
  14. CVE-2026-11981GiveWP <= 4.15.3 - Cross-Site Request Forgery4.3
  15. CVE-2026-12902Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions4.3

The record

Peak rank
#72 in Jan 2025
Busiest month shown
Jan 2025, 11 CVEs
Months with a KEV entry
0 since Feb 2024
Monthly snapshots
11 since 2024
Stellarwp's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store