bplugins 厂商相关 73 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。
bplugins 是一款面向 WordPress 的插件开发框架,旨在简化插件构建流程。截至最新统计,该框架已关联 72 条 CVE 漏洞。历史漏洞主要集中在远程代码执行、跨站脚本及权限绕过等高危类型,部分源于对输入验证和输出转义的疏忽。尽管其提升了开发效率,但底层安全机制的缺陷导致多次被利用,建议使用者严格审查依赖版本并及时更新,以规避潜在的系统入侵风险。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-27416 | WordPress PDF Poster插件<=2.4.1访问控制漏洞 — PDF PosterCWE-862 | 5.3 | Medium | 2026-05-07 |
| CVE-2026-6446 | My Social Feeds <=1.0.4 敏感信息泄露漏洞 — My Social Feeds – Social Feeds Embedder Plugin for WordPressCWE-522 | 5.4 | Medium | 2026-05-02 |
| CVE-2026-40729 | WordPress plugin 3D viewer – Embed 3D Models 安全漏洞 — 3D viewer – Embed 3D ModelsCWE-862 | 4.3 | Medium | 2026-04-15 |
| CVE-2026-32489 | WordPress plugin B Blocks 安全漏洞 — B BlocksCWE-862 | 6.5 | Medium | 2026-03-25 |
| CVE-2026-4120 | WordPress plugin Info Cards – Add Text and Media in Card Layouts 跨站脚本漏洞 — Info Cards – Add Text and Media in Card LayoutsCWE-79 | 6.4 | Medium | 2026-03-19 |
| CVE-2026-32416 | WordPress plugin PDF Poster 安全漏洞 — PDF PosterCWE-862 | 5.4 | Medium | 2026-03-13 |
| CVE-2026-32359 | WordPress plugin Icon List Block 跨站脚本漏洞 — Icon List BlockCWE-79 | 6.5 | Medium | 2026-03-13 |
| CVE-2026-1228 | WordPress plugin Timeline Block 安全漏洞 — Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines)CWE-639 | 4.3 | Medium | 2026-02-06 |
| CVE-2026-1294 | WordPress plugin All In One Image Viewer Block 代码问题漏洞 — All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlinkCWE-918 | 7.2 | High | 2026-02-05 |
| CVE-2026-1389 | WordPress plugin Document Embedder 安全漏洞 — Document Embedder – Embed PDFs, Word, Excel, and Other FilesCWE-639 | 4.3 | Medium | 2026-01-28 |
| CVE-2026-24565 | WordPress plugin B Accordion 安全漏洞 — B AccordionCWE-201 | 6.5 | Medium | 2026-01-23 |
| CVE-2026-24383 | WordPress plugin B Slider 跨站脚本漏洞 — B SliderCWE-79 | 6.5 | Medium | 2026-01-22 |
| CVE-2026-0833 | WordPress plugin Team Section Block 跨站脚本漏洞 — Team Section Block – Showcase Team Members with Layout OptionsCWE-79 | 6.4 | Medium | 2026-01-17 |
| CVE-2025-13999 | WordPress plugin HTML5 Audio Player 代码问题漏洞 — HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio PlayerCWE-918 | 7.2 | High | 2025-12-19 |
| CVE-2025-60079 | WordPress plugin Parallax Section block 安全漏洞 — Parallax Section blockCWE-862 | 7.1 | High | 2025-12-18 |
| CVE-2025-66110 | WordPress plugin Tiktok Feed 安全漏洞 — Tiktok FeedCWE-862 | 5.3 | Medium | 2025-11-21 |
| CVE-2025-12376 | WordPress plugin Icon List Block 代码问题漏洞 — Icon List Block – Add Icon-Based Lists with Custom StylesCWE-918 | 6.4 | Medium | 2025-11-18 |
| CVE-2025-54711 | WordPress plugin Info Cards 安全漏洞 — Info CardsCWE-862 | 7.1 | High | 2025-11-06 |
| CVE-2025-49900 | WordPress plugin Advanced scrollbar 安全漏洞 — Advanced scrollbarCWE-266 | 8.8 | High | 2025-11-06 |
| CVE-2025-49394 | WordPress plugin Image Gallery block – Create and display photo gallery/photo album 安全漏洞 — Image Gallery block – Create and display photo gallery/photo album.CWE-862 | 7.1 | High | 2025-11-06 |
| CVE-2025-12384 | WordPress plugin Document Embedder – Embed PDFs Word Excel and Other Files 安全漏洞 — Document Embedder – Embed PDFs, Word, Excel, and Other FilesCWE-862 | 8.6 | High | 2025-11-05 |
| CVE-2025-12388 | WordPress plugin B Carousel Block – Responsive Image and Content Carousel 代码问题漏洞 — Carousel Block – Responsive Image and Content CarouselCWE-918 | 6.4 | Medium | 2025-11-05 |
| CVE-2025-62007 | WordPress plugin Voice Feedback 安全漏洞 — Voice FeedbackCWE-266 | 8.8 | High | 2025-10-22 |
| CVE-2025-10735 | WordPress plugin Block For Mailchimp 代码问题漏洞 — Block for Mailchimp – Add Email Subscription Forms and Collect LeadsCWE-918 | 4.0 | Medium | 2025-10-01 |
| CVE-2025-9203 | WordPress plugin Media Player Addons for Elementor 跨站脚本漏洞 — Media Player Addons for Elementor – Audio and Video Widgets for ElementorCWE-79 | 6.4 | Medium | 2025-09-17 |
| CVE-2025-54734 | WordPress plugin B Slider 安全漏洞 — B SliderCWE-862 | 5.8 | Medium | 2025-08-28 |
| CVE-2025-54710 | WordPress plugin Tiktok Feed 安全漏洞 — Tiktok FeedCWE-862 | 7.1 | High | 2025-08-28 |
| CVE-2025-8676 | WordPress plugin B Slider 信息泄露漏洞 — bSlider – Create Responsive Image, Post, Product, and Video SlidersCWE-200 | 4.3 | Medium | 2025-08-15 |
| CVE-2025-8680 | WordPress plugin B Slider 代码问题漏洞 — bSlider – Create Responsive Image, Post, Product, and Video SlidersCWE-918 | 4.3 | Medium | 2025-08-15 |
| CVE-2025-54708 | WordPress plugin B Blocks 跨站脚本漏洞 — B BlocksCWE-79 | 6.5 | Medium | 2025-08-14 |
本页汇总了 bplugins 厂商截至目前公开的全部 73 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。