plugin

Bridge Core Vulnerabilities

10 known security issues reported for the Bridge Core WordPress plugin. Most recent disclosed Apr 1, 2025.

5 medium

Running Bridge Core on your site? Check whether your installed version is affected.

Scan your site free

Bridge Core [bridge-core] < 3.3.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Core allows Stored XSS. This issue affects Bridge Core: from n/a through n/a.

Affected:
up to 3.3.1
Fixed in:
3.3.1
Disclosed:
Apr 1, 2025

CVE-2025-31409 on NVD →

Bridge Core < 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute wh...

CVSS:
6.4
Affected:
up to 3.3.1
Fixed in:
3.3.1
Disclosed:
Mar 31, 2025

CVE-2025-31409 on NVD →

Bridge Core [bridge-core] < 3.3.1

unknown

[en] Missing Authorization vulnerability in NotFound Bridge Core. This issue affects Bridge Core: from n/a through 3.3.

Affected:
up to 3.3.1
Fixed in:
3.3.1
Disclosed:
Jan 27, 2025

CVE-2025-24744 on NVD →

Bridge Core <= 3.3 - Missing Authorization

medium

The Bridge Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.3
Fixed in:
3.3.1
Disclosed:
Jan 24, 2025

CVE-2025-24744 on NVD →

Bridge Core [bridge-core] < 3.3.1

unknown

[en] The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level pe...

Affected:
up to 3.3.1
Fixed in:
3.3.1
Disclosed:
Oct 12, 2024

CVE-2024-9860 on NVD →

Bridge Core <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Demo Import

medium

The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level permiss...

CVSS:
5.4
Affected:
up to 3.3
Fixed in:
3.3.1
Disclosed:
Oct 11, 2024

CVE-2024-9860 on NVD →

Bridge Core [bridge-core] < 3.3

unknown

[en] The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...

Affected:
up to 3.3
Fixed in:
3.3
Disclosed:
Oct 8, 2024

CVE-2024-9292 on NVD →

Bridge Core <= 3.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above...

CVSS:
6.4
Affected:
up to 3.2.0
Fixed in:
3.3
Disclosed:
Oct 7, 2024

CVE-2024-9292 on NVD →

Bridge Core [bridge-core] < 3.1.0

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Qode Interactive Bridge Core plugin <= 3.0.9 versions.

Affected:
up to 3.1.0
Fixed in:
3.1.0
Disclosed:
Sep 27, 2023

CVE-2023-40333 on NVD →

Bridge Core <= 3.0.9 - Reflected Cross-Site Scripting

medium

The Bridge Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 3.0.9
Fixed in:
3.1.0
Disclosed:
Aug 29, 2023

CVE-2023-40333 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database