📦 Spectra

by Brainstormforce

🔍 What is Spectra?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-36679

HIGH CVSS 7.1 Mar 28, 2024

This Server-Side Request Forgery (SSRF) vulnerability in the Spectra WordPress plugin allows attackers to make unauthorized requests from the vulnerable server to internal or external systems. It affe...

CVE-2023-23834

MEDIUM CVSS 4.3 Dec 9, 2024

This vulnerability allows attackers to bypass authorization controls in the Spectra WordPress plugin, potentially enabling unauthorized actions. It affects all WordPress sites using Spectra versions u...

CVE-2024-37517

MEDIUM CVSS 4.3 Nov 1, 2024

This CVE describes a Missing Authorization vulnerability in the Brainstorm Force Spectra WordPress plugin, allowing attackers to exploit incorrectly configured access control security levels. It affec...

CVE-2024-7590

MEDIUM CVSS 6.5 Aug 12, 2024

This stored XSS vulnerability in the Spectra WordPress plugin allows attackers to inject malicious scripts into web pages that are then executed when other users view those pages. It affects all WordP...

CVE-2023-36676

MEDIUM CVSS 5.4 Jun 19, 2024

This CVE describes a Missing Authorization vulnerability in the Spectra WordPress plugin (formerly Ultimate Addons for Gutenberg) that allows unauthorized users to perform actions they shouldn't have ...

CVE-2023-23735

MEDIUM CVSS 5.3 Jun 3, 2024

This vulnerability allows attackers to inject malicious HTML/JavaScript code into Spectra WordPress plugin pages through unauthenticated email input. It affects all WordPress sites using Spectra (form...

CVE-2024-4366

MEDIUM CVSS 6.4 May 24, 2024

The Spectra WordPress plugin has a stored XSS vulnerability in versions up to 2.13.0 that allows authenticated attackers with author-level permissions to inject malicious scripts into pages. These scr...

CVE-2024-1814

MEDIUM CVSS 6.4 May 23, 2024

The Spectra WordPress Gutenberg Blocks plugin has a stored XSS vulnerability in its Testimonial block. Authenticated attackers with contributor-level access or higher can inject malicious scripts that...

CVE-2024-3107

MEDIUM CVSS 4.3 May 2, 2024

The Spectra WordPress plugin (formerly Ultimate Addons for Gutenberg) has a path traversal vulnerability that allows authenticated users with contributor-level permissions or higher to read any attrib...