Unitecms develops WordPress plugin extensions, specifically unlimited add-ons for the WPBakery page builder, that expand visual composition capabilities for website administrators. The observed vulnerability surface centers on unrestricted file-upload handling, a characteristic weakness in plugin-based content management layers where access controls may be inadequately scoped. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unitecms over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6925HIGH The Unlimited Addons for WPBakery Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'importZipFile' function | Feb 5, 2024 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unitecms.
Media articles that mention a CVE ID that affects a product developed by Unitecms — matched by CVE ID, not by vendor name.