brainstormforce Vulnerabilities and Affected Products
Vulnerabilities associated with Starter Templates — Elementor, Gutenberg & Beaver Builder Templates.
Products
Clear product- Spectra Gutenberg Blocks – Website Builder for the Block Editor11 vulnerabilities
- Ultimate Addons for Elementor10 vulnerabilities
- SureForms – Contact Form, Payment Form & Other Custom Form Builder7 vulnerabilities
- Ultimate Addons for Beaver Builder – Lite5 vulnerabilities
- CartFlows – Funnel Builder & Checkout Plugin for WooCommerce3 vulnerabilities
- Starter Templates – AI-Powered Templates for Elementor & Gutenberg3 vulnerabilities
- ultimate_addons_for_elementor3 vulnerabilities
- Astra2 vulnerabilities
- Custom Fonts – Host Your Fonts Locally2 vulnerabilities
- OttoKit: All-in-One Automation Platform2 vulnerabilities
- spectra2 vulnerabilities
- SureForms – Drag and Drop Form Builder for WordPress2 vulnerabilities
- convertplug1 vulnerability
- Import / Export Customizer Settings1 vulnerability
- Lightweight Sidebar Manager1 vulnerability
- Spectra Legacy – Gutenberg Blocks1 vulnerability
- spectra_pro1 vulnerability
- Starter Templates — Elementor, Gutenberg & Beaver Builder Templates1 vulnerability
- starter_templates1 vulnerability
- Surecart1 vulnerability
- SureDash – Community, Courses & Member Dashboard1 vulnerability
- SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz1 vulnerability
- SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator1 vulnerability
- SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers1 vulnerability
- ultimate_addons_for_wpbakery_page_builder1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-42360HIGH | Starter Templates — Elementor, Gutenberg & Beaver Builder Templates <= 2.7.0 Authenticated Block Import to Stored XSSOn sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft and host a block containing malicious JavaScript on a server they controlled, and then use it to overwrite any post or page by sending an AJAX request with the action set to astra-page-elementor-batch-process and the url… | CVSS7.6v3.1 | EPSS0.585% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |