Vulnerabilities (CVE)

Filtered by vendor Pagebuildersandwich Subscribe
Filtered by product Page Builder Sandwich
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-1381 1 Pagebuildersandwich 1 Page Builder Sandwich 2025-04-01 N/A 6.5 MEDIUM
The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber access and higher, to extract sensitive user or configuration data.
CVE-2024-1285 1 Pagebuildersandwich 1 Page Builder Sandwich 2025-01-08 N/A 6.5 MEDIUM
The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'gambit_builder_save_content' function in all versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber access and above, to insert arbitrary content into existing posts.
CVE-2024-37219 1 Pagebuildersandwich 1 Page Builder Sandwich 2024-11-21 N/A 6.5 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PBN Hosting SL Page Builder Sandwich – Front-End Page Builder allows Stored XSS.This issue affects Page Builder Sandwich – Front-End Page Builder: from n/a through 5.1.0.