Siteorigin
Siteorigin Page Builder: vulnerabilidades y CVE
Siteorigin Page Builder tiene 9 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-97256 | Alta (7.2) | 0.54% | — | 30 sept 2026 | Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. |
| CVE-2026-13295 | Media (6.4) | 0.42% | — | 27 jun 2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.3 due to insufficient input sanitization and output… |
| CVE-2026-2448 | Alta (8.8) | 0.92% | — | 3 mar 2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.5 via the locate_template() function. This makes it possible for authenticated… |
| CVE-2025-1459 | Media (5.4) | 0.24% | — | 1 mar 2025 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Embedded Video(PB) widget in all versions up to, and including, 2.31.4 due to insufficient input sanitization and… |
| CVE-2024-12240 | Media (5.4) | 0.33% | — | 14 ene 2025 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label parameter in all versions up to, and including, 2.31.0 due to insufficient input sanitization and output… |
| CVE-2024-4361 | Media (5.4) | 0.36% | — | 21 may 2024 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 2.29.15 due to insufficient input… |
| CVE-2024-2202 | Media (5.4) | 0.43% | — | 23 mar 2024 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image widget in all versions up to, and including, 2.29.6 due to insufficient input sanitization and output… |
| CVE-2020-13643 | Alta (8.8) | 0.81% | — | 28 may 2020 | An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator.… |
| CVE-2020-13642 | Alta (8.8) | 0.81% | — | 28 may 2020 | An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.