plugin

Benaa Framework Vulnerabilities

6 known security issues reported for the Benaa Framework WordPress plugin. Most recent disclosed May 2, 2025.

1 high 2 medium

Running Benaa Framework on your site? Check whether your installed version is affected.

Scan your site free

Benaa [benaa-framework] <= 4.0.0 (unfixed)

unknown

[en] Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various versions. This makes it possible for authenticated attackers, w...

Affected:
up to 4.0.0
Fix:
No patched version reported
Disclosed:
May 2, 2025

CVE-2024-13420 on NVD →

Benaa [benaa-framework] <= 4.0.0 (unfixed)

unknown

[en] Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above,...

Affected:
up to 4.0.0
Fix:
No patched version reported
Disclosed:
May 2, 2025

CVE-2024-13419 on NVD →

Benaa [benaa-framework] <= 4.0.0 (unfixed)

unknown

[en] Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files that can make remote c...

Affected:
up to 4.0.0
Fix:
No patched version reported
Disclosed:
May 2, 2025

CVE-2024-13418 on NVD →

Smart Framework <= Multiple Plugins - Authenticated (Subscriber+) Arbitrary File Upload

high

Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files that can make remote code e...

CVSS:
8.8
Affected:
up to 4.0.0
Fix:
No patched version reported
Disclosed:
May 1, 2025

CVE-2024-13418 on NVD →

Smart Framework <= Multiple Plugins - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to u...

CVSS:
6.4
Affected:
up to 4.0.0
Fix:
No patched version reported
Disclosed:
May 1, 2025

CVE-2024-13419 on NVD →

Smart Framework <= Multiple Plugins - Missing Authorization to Authenticated (Subscriber+) Settings Updates

medium

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various versions. This makes it possible for authenticated attackers, with S...

CVSS:
4.3
Affected:
up to 4.0.0
Fix:
No patched version reported
Disclosed:
May 1, 2025

CVE-2024-13420 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database