Bread & Butter: Content Gating for Verified Leads <= 8.6.0.107 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
medium
The Bread & Butter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'breadbutter-customevent-button' shortcode in all versions up to, and including, 8.6.0.107. This is due to insufficient input sanitization and output escaping on the 'event' shortcode attribute. The customEventShortCodeButton()...
- CVSS:
- 6.4
- Affected:
- up to 8.6.0.107
- Fixed in:
- 8.7.0.139
- Disclosed:
- Apr 21, 2026
CVE-2026-4279 on NVD →
Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents <= 7.11.1374 - Cross-Site Request Forgery to Arbitrary File Upload
medium
The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.11.1374. This is due to missing or incorrect nonce validation on the uploadImage() function. This makes it possibl...
- CVSS:
- 4.3
- Affected:
- up to 7.11.1374
- Fixed in:
- 8.0.1398
- Disclosed:
- Dec 4, 2025
CVE-2025-12189 on NVD →
Lead capture, gated content & newsletter opt-ins <= 7.4.857 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Lead capture, gated content & newsletter opt-ins plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.4.857 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inj...
- CVSS:
- 6.4
- Affected:
- up to 7.4.857
- Fixed in:
- 7.5.880
- Disclosed:
- Nov 8, 2024
CVE-2024-51802 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database