plugin

Sitebuilder Dynamic Components Vulnerabilities

2 known security issues reported for the Sitebuilder Dynamic Components WordPress plugin. Most recent disclosed Oct 18, 2024.

2 critical

Running Sitebuilder Dynamic Components on your site? Check whether your installed version is affected.

Scan your site free

SiteBuilder Dynamic Components <= 1.0 - Unauthenticated PHP Object Injection

critical

The SiteBuilder Dynamic Components plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chai...

CVSS:
9.8
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Oct 18, 2024

CVE-2024-49625 on NVD →

SiteBuilder Dynamic Components <= 1.0 - PHP Object Injection

critical

The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.

CVSS:
9.8
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Apr 27, 2017

CVE-2017-18604 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database