Landing Page Builder <= 1.5.3.6 - Cross-Site Request Forgery to ulpb_admin_data AJAX Action
medium
The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.3.6. This is due to missing or incorrect nonce validation on the ulpb_admin_ajax function. This makes it possible f...
- CVSS:
- 4.3
- Affected:
- up to 1.5.3.6
- Fixed in:
- 1.5.3.7
- Disclosed:
- Jul 15, 2026
CVE-2026-12409 on NVD →
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages <= 1.5.3.5 - Unauthenticated Stored Cross-Site Scripting
high
The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t...
- CVSS:
- 7.2
- Affected:
- up to 1.5.3.5
- Fixed in:
- 1.5.3.6
- Disclosed:
- Jun 29, 2026
CVE-2026-57337 on NVD →
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages [page-builder-add] <= 1.5.3.3 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder page-builder-add allows Stored XSS.This issue affects Landing Page Builder: from n/a through <= 1.5.3.3.
- Affected:
- up to 1.5.3.3
- Fix:
- No patched version reported
- Disclosed:
- Jan 23, 2026
CVE-2026-24620 on NVD →
Landing Page Builder <= 1.5.3.4 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Landing Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in page...
- CVSS:
- 6.4
- Affected:
- up to 1.5.3.4
- Fixed in:
- 1.5.3.5
- Disclosed:
- Jan 10, 2026
CVE-2026-24620 on NVD →
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages [page-builder-add] < 1.5.2.1
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginOps Landing Page Builder allows PHP Local File Inclusion.This issue affects Landing Page Builder: from n/a through 1.5.2.0.
- Affected:
- up to 1.5.2.1
- Fixed in:
- 1.5.2.1
- Disclosed:
- Aug 19, 2024
CVE-2024-43345 on NVD →
Landing Page Builder <= 1.5.2.0 - Authenticated (Editor+) Local File Inlcusion
high
The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.5.2.0. This makes it possible for authenticated attackers, with Editor-level access and above, to include and execute arbit...
- CVSS:
- 7.2
- Affected:
- up to 1.5.2.0
- Fixed in:
- 1.5.2.1
- Disclosed:
- Aug 16, 2024
CVE-2024-43345 on NVD →
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages [page-builder-add] < 1.5.1.9
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Reflected XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.8.
- Affected:
- up to 1.5.1.9
- Fixed in:
- 1.5.1.9
- Disclosed:
- May 17, 2024
CVE-2024-34752 on NVD →
Landing Page Builder <= 1.5.1.8 - Reflected Cross-Site Scripting via pageType
medium
The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the pageType parameter in all versions up to, and including, 1.5.1.8 due to insufficient input sanitization and output escaping. This makes it possib...
- CVSS:
- 6.1
- Affected:
- up to 1.5.1.8
- Fixed in:
- 1.5.1.9
- Disclosed:
- May 14, 2024
CVE-2024-34752 on NVD →
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages [page-builder-add] < 1.5.1.8
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Stored XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.7.
- Affected:
- up to 1.5.1.8
- Fixed in:
- 1.5.1.8
- Disclosed:
- Mar 29, 2024
CVE-2024-30452 on NVD →
Landing Page Builder <= 1.5.1.7 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 1.5.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authentica...
- CVSS:
- 4.4
- Affected:
- up to 1.5.1.7
- Fixed in:
- 1.5.1.8
- Disclosed:
- Mar 28, 2024
CVE-2024-30452 on NVD →
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages [page-builder-add] < 1.5.1.6
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages.This issue affects Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages: from n/a through 1.5.1.5.
- Affected:
- up to 1.5.1.6
- Fixed in:
- 1.5.1.6
- Disclosed:
- Dec 7, 2023
CVE-2023-48325 on NVD →
Landing Page Builder <= 1.5.1.5 - Open Redirect
medium
The Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.5.1.5. This is due to insufficient validation on the redirect url supplied via user input or request parameter. This makes it possible fo...
- CVSS:
- 4.3
- Affected:
- up to 1.5.1.5
- Fixed in:
- 1.5.1.6
- Disclosed:
- Nov 23, 2023
CVE-2023-48325 on NVD →
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages [page-builder-add] < 1.5.1.3
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps Landing Page Builder plugin <= 1.5.1.2 versions.
- Affected:
- up to 1.5.1.3
- Fixed in:
- 1.5.1.3
- Disclosed:
- Sep 27, 2023
CVE-2023-40675 on NVD →
Landing Page Builder <= 1.5.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Landing Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.5.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arb...
- CVSS:
- 4.4
- Affected:
- up to 1.5.1.2
- Fixed in:
- 1.5.1.3
- Disclosed:
- Aug 22, 2023
CVE-2023-40675 on NVD →
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages [page-builder-add] < 1.4.9.9
unknown
[en] The Landing Page Builder WordPress plugin before 1.4.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users s...
- Affected:
- up to 1.4.9.9
- Fixed in:
- 1.4.9.9
- Disclosed:
- Jan 23, 2023
CVE-2022-4718 on NVD →
Landing Page Builder <= 1.4.9.8.9 - Authenticated (Contributor+) Cross-Site Scripting via Shortcode
medium
The Landing Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 1.4.9.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor le...
- CVSS:
- 6.4
- Affected:
- up to 1.4.9.8.9
- Fixed in:
- 1.4.9.9
- Disclosed:
- Dec 27, 2022
CVE-2022-4718 on NVD →
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages [page-builder-add] < 1.4.9.6
unknown
[en] The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.
- Affected:
- up to 1.4.9.6
- Fixed in:
- 1.4.9.6
- Disclosed:
- Jan 17, 2022
CVE-2021-25067 on NVD →
Landing Page Builder <= 1.4.9.5 - Reflected Cross-Site Scripting
medium
The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.
- CVSS:
- 6.1
- Affected:
- up to 1.4.9.5
- Fixed in:
- 1.4.9.6
- Disclosed:
- Dec 16, 2021
CVE-2021-25067 on NVD →
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages [page-builder-add] < 1.4.4
unknown
Authenticated Local File Inclusion (LFI) Vulnerability exists in 1.4.3 version in the function pb_shortcode_sample_nav(). It allows an attacker to include local files by using menu_class shortcode argument in pb_samlple_nav shortcode.
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Oct 30, 2017
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database