Bridge Core [bridge-core] < 3.3.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Core allows Stored XSS. This issue affects Bridge Core: from n/a through n/a.
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.1
- Disclosed:
- Apr 1, 2025
CVE-2025-31409 on NVD →
Bridge Core < 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute wh...
- CVSS:
- 6.4
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.1
- Disclosed:
- Mar 31, 2025
CVE-2025-31409 on NVD →
Bridge Core [bridge-core] < 3.3.1
unknown
[en] Missing Authorization vulnerability in NotFound Bridge Core. This issue affects Bridge Core: from n/a through 3.3.
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.1
- Disclosed:
- Jan 27, 2025
CVE-2025-24744 on NVD →
Bridge Core <= 3.3 - Missing Authorization
medium
The Bridge Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.3
- Fixed in:
- 3.3.1
- Disclosed:
- Jan 24, 2025
CVE-2025-24744 on NVD →
Bridge Core [bridge-core] < 3.3.1
unknown
[en] The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level pe...
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.1
- Disclosed:
- Oct 12, 2024
CVE-2024-9860 on NVD →
Bridge Core <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Demo Import
medium
The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level permiss...
- CVSS:
- 5.4
- Affected:
- up to 3.3
- Fixed in:
- 3.3.1
- Disclosed:
- Oct 11, 2024
CVE-2024-9860 on NVD →
Bridge Core [bridge-core] < 3.3
unknown
[en] The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...
- Affected:
- up to 3.3
- Fixed in:
- 3.3
- Disclosed:
- Oct 8, 2024
CVE-2024-9292 on NVD →
Bridge Core <= 3.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above...
- CVSS:
- 6.4
- Affected:
- up to 3.2.0
- Fixed in:
- 3.3
- Disclosed:
- Oct 7, 2024
CVE-2024-9292 on NVD →
Bridge Core [bridge-core] < 3.1.0
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Qode Interactive Bridge Core plugin <= 3.0.9 versions.
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
- Disclosed:
- Sep 27, 2023
CVE-2023-40333 on NVD →
Bridge Core <= 3.0.9 - Reflected Cross-Site Scripting
medium
The Bridge Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 3.0.9
- Fixed in:
- 3.1.0
- Disclosed:
- Aug 29, 2023
CVE-2023-40333 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database