Brainstormforce develops a portfolio of WordPress page builders and form-management plugins that extend functionality for content creators and site administrators across a substantial ecosystem of WordPress installations. Despite a focused product line, the vendor's presence in the WordPress plugin landscape positions it prominently among affected vendors in vulnerability tracking. The recurring weaknesses center on client-side and server-side input handling—particularly cross-site scripting, missing authorization checks, and path traversal flaws—alongside request-forgery issues that are characteristic of web-application plugins operating in shared WordPress environments where permission boundaries and input sanitization are critical. Defenders deploying these plugins should prioritize updates and audit user-role assignments and file-access controls on affected sites. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Brainstormforce over time
Signals from CVEs in this vendor scope (93 CVEs).
93 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24507CRITICAL The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infin | Aug 9, 2021 | 9.8 | 35 | NO | NO |
CVE-2026-15787MEDIUM The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all ve | Jul 22, 2026 | 6.4 | 30 | NO | NO |
CVE-2020-13125MEDIUM An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthen | May 17, 2020 | 6.5 | 28 | NO | YES |
CVE-2023-23834CRITICAL Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through | Dec 9, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-36684CRITICAL Missing Authorization vulnerability in Brainstorm Force Convert Pro.This issue affects Convert Pro: from n/a through 1.7.5. | Jun 19, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-46851HIGH Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions. | May 23, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-25058HIGH Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions. | May 26, 2023 | 8.8 | 26 | NO | NO |
CVE-2025-6691HIGH The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_ | Jul 9, 2025 | 8.1 | 25 | NO | NO |
CVE-2024-37455HIGH Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a | Jul 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-44148HIGH Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7. | Jun 19, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (93 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Brainstormforce.
Media articles that mention a CVE ID that affects a product developed by Brainstormforce — matched by CVE ID, not by vendor name.