Wpmudev
Wpmudev Branda: vulnerabilidades y CVE
Wpmudev Branda tiene 8 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses3
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-102376 | Alta (7.1) | 0.25% | — | 30 sept 2026 | Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions. |
| CVE-2026-11551 | Crítica (9.8) | 0.62% | — | 20 jun 2026 | The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to… |
| CVE-2025-14998 | Crítica (9.8) | 1.9% | — | 2 ene 2026 | The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to… |
| CVE-2024-9371 | Media (6.1) | 0.55% | — | 21 nov 2024 | The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all… |
| CVE-2024-37239 | Media (4.8) | 0.26% | — | 22 jul 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Branda branda-white-labeling.This issue affects Branda: from n/a… |
| CVE-2024-6554 | Media (5.3) | 0.45% | — | 11 jul 2024 | The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.18. This is due the plugin utilizing composer without… |
| CVE-2024-5191 | Media (5.4) | 0.31% | — | 21 jun 2024 | The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mime_types’ parameter in all versions up to, and including, 3.4.17 due to… |
| CVE-2023-51542 | Media (5.3) | 0.37% | — | 4 jun 2024 | Authentication Bypass by Spoofing vulnerability in WPMU DEV Branda allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Branda: from n/a through 3.4.14. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.