VYPR

Spectra Pro

by WordPress

CVEs (3)

  • CVE-2024-3828HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. This is due to the plugin allowing lower-privileged users to create registration forms and set the default role to administrator This makes it possible for…

  • CVE-2024-3827MedAug 2, 2024
    risk 0.42cvss 6.4epss 0.00

    The Spectra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block ids in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…

  • CVE-2020-36656MedFeb 21, 2023
    risk 0.35cvss 5.4epss 0.01

    The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.