plugin

Branda White Labeling Vulnerabilities

16 known security issues reported for the Branda White Labeling WordPress plugin. Most recent disclosed Jun 19, 2026.

2 critical 6 medium

Running Branda White Labeling on your site? Check whether your installed version is affected.

Scan your site free

Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover

critical

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's p...

CVSS:
9.8
Affected:
up to 3.4.29
Fixed in:
3.4.31
Disclosed:
Jun 19, 2026

CVE-2026-11551 on NVD →

Branda – White Label &amp; Branding, Free Login Page Customizer [branda-white-labeling] < 3.4.29

unknown

[en] The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary use...

Affected:
up to 3.4.29
Fixed in:
3.4.29
Disclosed:
Jan 2, 2026

CVE-2025-14998 on NVD →

Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via Account Takeover

critical

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's p...

CVSS:
9.8
Affected:
up to 3.4.24
Fixed in:
3.4.29
Disclosed:
Jan 1, 2026

CVE-2025-14998 on NVD →

Branda – White Label &amp; Branding, Free Login Page Customizer [branda-white-labeling] < 3.4.22

unknown

[en] The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.19. This makes it possible for unauthenticated attackers to inj...

Affected:
up to 3.4.22
Fixed in:
3.4.22
Disclosed:
Nov 21, 2024

CVE-2024-9371 on NVD →

Branda – White Label & Branding, Custom Login Page Customizer <= 3.4.19 - Reflected Cross-Site Scripting

medium

The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.19. This makes it possible for unauthenticated attackers to inject a...

CVSS:
6.1
Affected:
up to 3.4.21
Fixed in:
3.4.22
Disclosed:
Nov 20, 2024

CVE-2024-9371 on NVD →

Branda – White Label &amp; Branding, Free Login Page Customizer [branda-white-labeling] < 3.4.18

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Branda allows Stored XSS.This issue affects Branda: from n/a through 3.4.17.

Affected:
up to 3.4.18
Fixed in:
3.4.18
Disclosed:
Jul 22, 2024

CVE-2024-37239 on NVD →

Branda – White Label &amp; Branding, Free Login Page Customizer [branda-white-labeling] < 3.4.19

unknown

[en] The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.18. This is due the plugin utilizing composer without preventing direct access to the files. This makes it possible for unauthenticated attackers to...

Affected:
up to 3.4.19
Fixed in:
3.4.19
Disclosed:
Jul 11, 2024

CVE-2024-6554 on NVD →

Branda – White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path Disclosure

medium

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.18. This is due the plugin utilizing composer without preventing direct access to the files. This makes it possible for unauthenticated attackers to retri...

CVSS:
5.3
Affected:
up to 3.4.18
Fixed in:
3.4.19
Disclosed:
Jul 10, 2024

CVE-2024-6554 on NVD →

Branda <= 3.4.17 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Branda plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
4.4
Affected:
up to 3.4.17
Fixed in:
3.4.18
Disclosed:
Jun 28, 2024

CVE-2024-37239 on NVD →

Branda – White Label &amp; Branding, Free Login Page Customizer [branda-white-labeling] < 3.4.18

unknown

[en] The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mime_types’ parameter in all versions up to, and including, 3.4.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacke...

Affected:
up to 3.4.18
Fixed in:
3.4.18
Disclosed:
Jun 21, 2024

CVE-2024-5191 on NVD →

Branda – White Label WordPress, Custom Login Page Customizer <= 3.4.17 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload

medium

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mime_types’ parameter in all versions up to, and including, 3.4.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w...

CVSS:
6.4
Affected:
up to 3.4.17
Fixed in:
3.4.18
Disclosed:
Jun 20, 2024

CVE-2024-5191 on NVD →

Branda – White Label &amp; Branding, Free Login Page Customizer [branda-white-labeling] < 3.4.15

unknown

[en] Authentication Bypass by Spoofing vulnerability in WPMU DEV Branda allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Branda: from n/a through 3.4.14.

Affected:
up to 3.4.15
Fixed in:
3.4.15
Disclosed:
Jun 4, 2024

CVE-2023-51542 on NVD →

Branda <= 3.4.14 - IP Address Spoofing

medium

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 3.4.14 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthe...

CVSS:
5.3
Affected:
up to 3.4.14
Fixed in:
3.4.15
Disclosed:
Dec 27, 2023

CVE-2023-51542 on NVD →

Branda – White Label &amp; Branding, Free Login Page Customizer [branda-white-labeling] < 3.4.9

unknown

Update the WordPress Branda plugin to the latest available version (at least 3.4.9). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Branda Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into y...

Affected:
up to 3.4.9
Fixed in:
3.4.9
Disclosed:
Mar 20, 2023

Branda – White Label WordPress <= 3.4.8.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Branda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.4.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary we...

CVSS:
4.4
Affected:
up to 3.4.8.1
Fixed in:
3.4.9
Disclosed:
Mar 16, 2023

Branda – White Label &amp; Branding, Free Login Page Customizer [branda-white-labeling] < 3.4.9

unknown

The Branda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.4.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary we...

Affected:
up to 3.4.9
Fixed in:
3.4.9
Disclosed:
Mar 16, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database