plugin

Salient Core Vulnerabilities

4 known security issues reported for the Salient Core WordPress plugin. Most recent disclosed Oct 8, 2025.

1 high 3 medium

Running Salient Core on your site? Check whether your installed version is affected.

Scan your site free

Salient Core <= 3.0.8 - Missing Authorization

medium

The Salient | Creative Multipurpose & WooCommerce Theme plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.0.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unautho...

CVSS:
4.3
Affected:
up to 3.0.8
Fixed in:
3.0.9
Disclosed:
Oct 8, 2025

CVE-2025-59001 on NVD →

Salient Core <= 2.0.7 - Authenticated (Contributor+) Local File Inclusion via Shortcode

high

The Salient Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.7 via the 'nectar_icon' shortcode 'icon_linea' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the...

CVSS:
7.5
Affected:
up to 2.0.7
Fixed in:
2.0.8
Disclosed:
Apr 17, 2024

CVE-2024-3812 on NVD →

Salient Core <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The salient-core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level a...

CVSS:
6.4
Affected:
up to 2.0.2
Fixed in:
2.0.3
Disclosed:
Nov 24, 2023

CVE-2023-48749 on NVD →

Salient Core <= 2.0.2 - Reflected Cross-Site Scripting

medium

The salient-core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

CVSS:
6.1
Affected:
up to 2.0.2
Fixed in:
2.0.3
Disclosed:
Nov 24, 2023

CVE-2023-48748 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database