plugin

Pearl Header Builder Vulnerabilities

6 known security issues reported for the Pearl Header Builder WordPress plugin. Most recent disclosed Apr 1, 2025.

6 medium

Running Pearl Header Builder on your site? Check whether your installed version is affected.

Scan your site free

Pearl <= 1.3.9 - Cross-Site Request Forgery

medium

The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.9. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted the...

CVSS:
4.3
Affected:
up to 1.3.9
Fixed in:
1.3.10
Disclosed:
Apr 1, 2025

CVE-2025-31880 on NVD →

Pearl <= 1.3.9 - Missing Authorization

medium

The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action...

CVSS:
4.3
Affected:
up to 1.3.9
Fixed in:
1.3.10
Disclosed:
Apr 1, 2025

CVE-2025-31881 on NVD →

Wordpress Header Builder Plugin <= 1.3.8 - Cross-Site Request Forgery to Header Deletion

medium

The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This is due to missing or incorrect nonce validation on the stm_header_builder page. This makes it possible for unauthenticated attackers to delete arbitrary headers...

CVSS:
4.3
Affected:
up to 1.3.8
Fixed in:
1.3.9
Disclosed:
Jan 8, 2025

CVE-2024-12206 on NVD →

WordPress Header Builder Plugin – Pearl <= 1.3.7 - Missing Authorization to Unauthenticated Arbitrary Site Options Deletion

medium

The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to unauthorized site option deletion due to a missing validation and capability checks on the stm_hb_delete() function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to delete arbitrary opti...

CVSS:
6.5
Affected:
up to 1.3.7
Fixed in:
1.3.8
Disclosed:
Jun 11, 2024

CVE-2024-5468 on NVD →

WordPress Header Builder Plugin – Pearl <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_hb' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...

CVSS:
6.4
Affected:
up to 1.3.6
Fixed in:
1.3.7
Disclosed:
Apr 30, 2024

CVE-2024-4000 on NVD →

Pearl <= 1.3.4 - Cross-Site Request Forgery via stm_save_hb_settings

medium

The Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.4. This is due to missing or incorrect nonce validation on the stm_save_hb_settings function. This makes it possible for unauthenticated attackers to create new or modify existing site headers via a forged r...

CVSS:
4.3
Affected:
up to 1.3.4
Fixed in:
1.3.5
Disclosed:
Apr 19, 2023

CVE-2022-38356 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database