VulnSea

builderall has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.4 (medium).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.4
Publish → KEV
Last 90 days
3 prev 0

Weakness classes

Products

  • Builderall for WordPress 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

builderall vulnerabilities

CVEs affecting builderall, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-15823Medium· 4.3
1w ago

Builderall for WordPress <= 3.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'ba_cheetah_data[post_id]' Parameter

The Builderall Cheetah For Wp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disable() function in versions up to, and including, 3.0.2. The wp_ajax_ba_cheetah_disable AJA…

Sunlitbuilderall · Builderall for WordPressEPSS 0.21%via CVEORG
CVE-2026-15796Medium· 6.4
1w ago

Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_video_service_url' Setting

The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bg_video_service_url' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. Thi…

Sunlitbuilderall · Builderall for WordPressEPSS 0.19%via CVEORG
CVE-2026-15820Medium· 6.4
1w ago

The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping

The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. …

Sunlitbuilderall · Builderall for WordPressEPSS 0.20%via NVD
builderall vulnerabilities (CVEs) · VulnSea