Medium 6.5
2025-09-22< 1.2.5.4
Ibtana <= 1.2.5.3 - Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion
Minimum safe version
1.2.5.8
Update to 1.2.5.8 or later to address 9 fixable vulnerabilities
Ibtana <= 1.2.5.3 - Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion
Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library
Ibtana - WordPress Website Builder <= 1.2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WordPress Ibtana plugin <= 1.2.5.9 - Cross Site Scripting (XSS) vulnerability
CVE-2024-8282
CVE-2024-37123
CVE-2024-5541
CVE-2023-6684
CVE-2022-4674
CVE-2021-25014