Kadence Starter Templates — Predesigned Website Templates <= 2.3.3 - Unauthenticated Denial of Service
medium
The Kadence Starter Templates — Predesigned Website Templates plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to compromise the availability of a site.
- CVSS:
- 5.3
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.4
- Disclosed:
- Aug 14, 2026
CVE-2026-73997 on NVD →
Starter Templates by Kadence WP <= 1.2.16 - Authenticated (Admin+) PHP Object Injection
medium
The Starter Templates by Kadence WP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.16 via the 'import_customizer_options' function. This allows authenticated users with administratior-level capabilities to inject a PHP Object. No POP chain is present in the vulnerable p...
- CVSS:
- 6.6
- Affected:
- up to 1.2.16
- Fixed in:
- 1.2.17
- Disclosed:
- Dec 1, 2022
CVE-2022-3679 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database