目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

bplugins 厂商漏洞列表 / CVE 中文分析 73

bplugins 厂商相关 73 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

bplugins 是一款面向 WordPress 的插件开发框架,旨在简化插件构建流程。截至最新统计,该框架已关联 72 条 CVE 漏洞。历史漏洞主要集中在远程代码执行、跨站脚本及权限绕过等高危类型,部分源于对输入验证和输出转义的疏忽。尽管其提升了开发效率,但底层安全机制的缺陷导致多次被利用,建议使用者严格审查依赖版本并及时更新,以规避潜在的系统入侵风险。

CVE IDタイトルCVSS深刻度公開日
CVE-2024-10667 Content Slider Block – Create fully functional slider with Gutenberg block <= 3.1.5 - Authenticated (Contributor+) Post Disclosure — Content Slider Block – Slide Through Text or Media ContentCWE-639 4.3 Medium2024-11-09
CVE-2024-10669 Countdown Timer block – Display the event's date into a timer. <= 1.2.4 - Authenticated (Contributor+) Post Disclosure — Countdown Timer Block – Animated Countdown for Events or LaunchesCWE-639 4.3 Medium2024-11-09
CVE-2024-47631 WordPress Logo Carousel – Clients logo carousel for WP plugin <= 1.2 - Cross Site Scripting (XSS) vulnerability — Logo Carousel – Clients logo carousel for WPCWE-79 6.5 Medium2024-10-05
CVE-2024-7727 HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handler — HTML5 Video Player – Embed and Play Videos in Custom PlayerCWE-862 5.3 Medium2024-09-11
CVE-2024-7721 HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update — HTML5 Video Player – Embed and Play Videos in Custom PlayerCWE-862 4.3 Medium2024-09-11
CVE-2024-43148 WordPress StreamCast <= 2.2.3 - Stored Cross Site Scripting (XSS) vulnerability — StreamCastCWE-79 5.9 Medium2024-08-12
CVE-2024-37445 WordPress HTML5 Audio Player plugin <= 2.2.23 - Cross Site Scripting (XSS) vulnerability — Html5 Audio PlayerCWE-79 6.5 Medium2024-07-22
CVE-2024-4398 HTML5 Audio Player- Best WordPress Audio Player Plugin <= 2.2.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets — HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio PlayerCWE-79 6.4 Medium2024-05-10
CVE-2024-0908 Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page <= 1.13.4 - Missing Authorization to Information Disclosure — Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and FiltersCWE-862 5.3 Medium2024-05-02
CVE-2024-30432 WordPress B Slider plugin <= 1.1.12 - Cross Site Scripting (XSS) vulnerability — B Slider - Slider for your block editorCWE-79 6.5 Medium2024-03-29
CVE-2024-30438 WordPress Print Page block plugin <= 1.0.8 - Cross Site Scripting (XSS) vulnerability — Print Page blockCWE-79 6.5 Medium2024-03-29
CVE-2024-23508 WordPress PDF Poster - PDF Embedder Plugin for WordPress Plugin <= 2.1.17 is vulnerable to Cross Site Scripting (XSS) — PDF Poster – PDF Embedder Plugin for WordPressCWE-79 7.1 High2024-01-31
CVE-2023-5860 Icons Font Loader <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Upload — Icons Font Loader – Load Web Fonts and Icon LibrariesCWE-434 7.2 High2023-11-02

本页汇总了 bplugins 厂商截至目前公开的全部 73 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。