Pluginops

Landing Page Builder

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 23.01.2026 14:29:06
  • Zuletzt bearbeitet 27.01.2026 20:16:24

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder page-builder-add allows Stored XSS.This issue affects Landing Page Builder: from n/a through <= 1.5.3.3.

  • EPSS 0.71%
  • Veröffentlicht 19.08.2024 20:15:08
  • Zuletzt bearbeitet 20.08.2024 15:44:20

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginOps Landing Page Builder allows PHP Local File Inclusion.This issue affects Landing Page Builder: from n/a through 1.5.2.0.

  • EPSS 0.56%
  • Veröffentlicht 17.05.2024 06:15:52
  • Zuletzt bearbeitet 21.11.2024 09:19:19

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Reflected XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.8.

  • EPSS 0.15%
  • Veröffentlicht 29.03.2024 17:15:16
  • Zuletzt bearbeitet 21.11.2024 09:11:57

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Stored XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.7.

  • EPSS 0.24%
  • Veröffentlicht 07.12.2023 12:15:08
  • Zuletzt bearbeitet 21.11.2024 08:31:29

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages.This issue affects Landing Page Builder – Lead Page – Optin Page – Squeeze Page – Wo...

  • EPSS 0.12%
  • Veröffentlicht 27.09.2023 15:19:23
  • Zuletzt bearbeitet 21.11.2024 08:19:57

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps Landing Page Builder plugin <= 1.5.1.2 versions.

Exploit
  • EPSS 0.2%
  • Veröffentlicht 23.01.2023 15:15:17
  • Zuletzt bearbeitet 03.04.2025 20:15:19

The Landing Page Builder WordPress plugin before 1.4.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scr...