Siteorigin develops WordPress page-builder and widget plugins that extend site customization and content creation capabilities for a broadly used platform, placing the vendor in a prominent position across web properties. The vendor's vulnerability exposure clusters around web-application input handling and access-control concerns, with recurring weakness classes including cross-site scripting, CSRF, and authorization gaps that are characteristic of user-facing content-management extensions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Siteorigin over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-54268HIGH Missing Authorization vulnerability in Greg - SiteOrigin SiteOrigin Widgets Bundle so-widgets-bundle allows Exploiting Incorrectly Configured Access Control Security Levels.This is | Dec 13, 2024 | 8.8 | 23 | NO | NO |
CVE-2023-6295HIGH The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the ad | Dec 18, 2023 | 7.2 | 22 | NO | NO |
CVE-2020-13643HIGH An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be f | May 28, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-13642HIGH An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requ | May 28, 2020 | 8.8 | 22 | NO | NO |
CVE-2025-1459MEDIUM The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Embedded Video(PB) widget in all versions up to, and including, 2.31.4 due | Mar 1, 2025 | 5.4 | 19 | NO | NO |
CVE-2024-4361MEDIUM The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including | May 21, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-2202MEDIUM The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image widget in all versions up to, and including, 2.29.6 due to ins | Mar 23, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-1070MEDIUM The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the features attribute in all versions up to, and including, 1.58.2 due to insuf | Feb 29, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-12240MEDIUM The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label parameter in all versions up to, and including, 2.31.0 due to ins | Jan 14, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-4362MEDIUM The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, | May 22, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Siteorigin.
Media articles that mention a CVE ID that affects a product developed by Siteorigin — matched by CVE ID, not by vendor name.