Builderall for WordPress <= 3.0.1 - Missing Authorization to Unauthenticated OAuth Update
medium
The Builderall for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.0.1. This makes it possible for unauthenticated attackers to update an OAuth connection.
- CVSS:
- 5.3
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.2
- Disclosed:
- Jul 20, 2026
CVE-2026-11882 on NVD →
Builderall for WordPress <= 3.0.1 - Authenticated (Contributor+) Remote Code Execution
high
The Builderall for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.0.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
- CVSS:
- 8.8
- Affected:
- up to 3.0.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 25, 2026
CVE-2026-22390 on NVD →
Builderall for WordPress [builderall-cheetah-for-wp] <= 3.0.1 (unfixed + closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Stored XSS.This issue affects Builderall Builder for WordPress: from n/a through <= 3.0.1.
- Affected:
- up to 3.0.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 27, 2025
CVE-2025-62987 on NVD →
Builderall Builder for WordPress <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Builderall Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...
- CVSS:
- 6.4
- Affected:
- up to 3.0.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 23, 2025
CVE-2025-62987 on NVD →
Builderall for WordPress [builderall-cheetah-for-wp] < 2.0.2 (closed)
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Builderall Team Builderall Builder for WordPress.This issue affects Builderall Builder for WordPress: from n/a through 2.0.1.
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- Apr 2, 2024
CVE-2024-30532 on NVD →
Builderall Builder for WordPress <= 2.0.1 - Unauthenticated Server-Side Request Forgery
high
The Builderall Builder for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.1. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which can be used to query and modify...
- CVSS:
- 7.2
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Mar 29, 2024
CVE-2024-30532 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database