Starter Templates – AI-Powered Templates for Elementor & Gutenberg [astra-sites] < 4.4.42
unknown
[en] The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possib...
- Affected:
- up to 4.4.42
- Fixed in:
- 4.4.42
- Disclosed:
- Dec 6, 2025
CVE-2025-13065 on NVD →
Starter Templates <= 4.4.41 - Authenticated (Author+) Arbitrary File Upload via WXR Upload Bypass
high
The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible fo...
- CVSS:
- 8.8
- Affected:
- up to 4.4.41
- Fixed in:
- 4.4.42
- Disclosed:
- Dec 5, 2025
CVE-2025-13065 on NVD →
Starter Templates <= 4.4.9 - Cross-Site Request Forgery
medium
The Starter Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.9. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 4.4.9
- Fixed in:
- 4.4.10
- Disclosed:
- Jan 24, 2025
CVE-2025-24568 on NVD →
Starter Templates – AI-Powered Templates for Elementor & Gutenberg [astra-sites] < 4.4.10
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates allows Cross Site Request Forgery. This issue affects Starter Templates: from n/a through 4.4.9.
- Affected:
- up to 4.4.10
- Fixed in:
- 4.4.10
- Disclosed:
- Jan 24, 2025
CVE-2025-24568 on NVD →
Starter Templates – AI-Powered Templates for Elementor & Gutenberg [astra-sites] < 4.4.1
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates allows Stored XSS.This issue affects Starter Templates: from n/a through 4.4.0.
- Affected:
- up to 4.4.1
- Fixed in:
- 4.4.1
- Disclosed:
- Oct 6, 2024
CVE-2024-47345 on NVD →
Starter Templates <= 4.4.0 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Starter Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 4.4.0
- Fixed in:
- 4.4.1
- Disclosed:
- Sep 27, 2024
CVE-2024-47345 on NVD →
Starter Templates – AI-Powered Templates for Elementor & Gutenberg [astra-sites] < 3.2.6
unknown
[en] Missing Authorization vulnerability in Brainstorm Force Premium Starter Templates, Brainstorm Force Starter Templates astra-sites.This issue affects Premium Starter Templates: from n/a through 3.2.5; Starter Templates: from n/a through 3.2.5.
- Affected:
- up to 3.2.6
- Fixed in:
- 3.2.6
- Disclosed:
- Jun 19, 2024
CVE-2023-41805 on NVD →
Starter Templates – AI-Powered Templates for Elementor & Gutenberg [astra-sites] < 4.2.2
unknown
[en] The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticat...
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.2
- Disclosed:
- May 11, 2024
CVE-2024-4630 on NVD →
Starter Templates — Elementor, WordPress & Beaver Builder Templates <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...
- CVSS:
- 6.4
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- May 10, 2024
CVE-2024-4630 on NVD →
Starter Templates – AI-Powered Templates for Elementor & Gutenberg [astra-sites] < 4.1.7
unknown
[en] The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.6 via the ai_api_request(). This makes it possible for authenticated attackers, with contributor-level access and above, to make web re...
- Affected:
- up to 4.1.7
- Fixed in:
- 4.1.7
- Disclosed:
- May 9, 2024
CVE-2024-1467 on NVD →
Starter Templates — Elementor, WordPress & Beaver Builder Templates <= 4.1.6 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.6 via the ai_api_request(). This makes it possible for authenticated attackers, with contributor-level access and above, to make web request...
- CVSS:
- 4.3
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.7
- Disclosed:
- May 8, 2024
CVE-2024-1467 on NVD →
Starter Templates – AI-Powered Templates for Elementor & Gutenberg [astra-sites] < 3.2.5
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates, Brainstorm Force Premium Starter Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4; Premium Starter Templa...
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- Mar 28, 2024
CVE-2023-34370 on NVD →
Starter Templates – AI-Powered Templates for Elementor & Gutenberg [astra-sites] < 3.2.5
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4.
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- Dec 7, 2023
CVE-2023-41804 on NVD →
Starter Templates <= 3.2.4 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The Starter Templates (free and premium) plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.2.4 via the remote_request. This can allow authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web...
- CVSS:
- 6.4
- Affected:
- up to 3.2.4
- Fixed in:
- 3.2.5
- Disclosed:
- Sep 5, 2023
CVE-2023-41804 on NVD →
Starter Templates <= 3.2.5 - Incorrect Authorization
medium
The Starter Templates (free and premium) plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect capability check on the sse_import() function in versions up to, and including, 3.2.5. This makes it possible for authenticated attackers, with contributor-level access and above, to impo...
- CVSS:
- 4.3
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.6
- Disclosed:
- Sep 5, 2023
CVE-2023-41805 on NVD →
Starter Templates – AI-Powered Templates for Elementor & Gutenberg [astra-sites] < 3.1.21
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions.
- Affected:
- up to 3.1.21
- Fixed in:
- 3.1.21
- Disclosed:
- May 23, 2023
CVE-2022-46851 on NVD →
Starter Templates — Elementor, WordPress & Beaver Builder Templates <= 3.1.20 - Cross-Site Request Forgery in add_to_favorite
medium
The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.20. This is due to missing or incorrect nonce validation on the add_to_favorite function. This makes it possible for unauthenticated attackers to...
- CVSS:
- 4.3
- Affected:
- up to 3.1.20
- Fixed in:
- 3.2.21
- Disclosed:
- Feb 20, 2023
CVE-2022-46851 on NVD →
Starter Templates – AI-Powered Templates for Elementor & Gutenberg [astra-sites] < 2.7.1
unknown
[en] On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft and host a block containing malicio...
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.1
- Disclosed:
- Nov 17, 2021
CVE-2021-42360 on NVD →
Starter Templates — Elementor, Gutenberg & Beaver Builder Templates <= 2.7.0 - Missing Authorization to Stored Cross-Site Scripting
high
On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft and host a block containing malicious Ja...
- CVSS:
- 7.6
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.1
- Disclosed:
- Oct 4, 2021
CVE-2021-42360 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database