Extension WordPress

Vulnérabilités Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons, page 2

Cette page rassemble les failles publiées pour Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons, leurs plages de versions affectées et les correctifs signalés dans la base locale.

38Vulnérabilités
1Critiques
38Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

38 fiches

CVE-2024-47392 Moyenne · 6,4
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons <= 5.7.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Element Pack Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-5.7.5

Correctif

5.7.6

Publication

30/09/2024

CVE-2024-7247 Moyenne · 6,4
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Gallery and Countdown widgets in all versions up to, and…

Versions affectées

*-5.7.2

Correctif

5.7.3

Publication

12/08/2024

CVE-2024-4359 Moyenne · 6,5
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 – Authenticated (Contributor+) Arbitrary File Read

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 5.7.2 via the SVG widget and a…

Versions affectées

*-5.7.2

Correctif

5.7.3

Publication

08/08/2024

CVE-2024-4360 Moyenne · 6,4
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 5.7.6 due to…

Versions affectées

*-5.7.6

Correctif

5.7.7

Publication

08/08/2024

CVE-2024-4643 Moyenne · 6,4
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘end_redirect_link’ parameter in versions up to, and including, 5.7.1 due to insufficient…

Versions affectées

*-5.6.11

Correctif

5.6.12

Publication

01/08/2024

CVE-2024-5554 Moyenne · 6,4
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘onclick_event’ parameter in all versions up to, and including, 5.6.11 due to…

Versions affectées

*-5.6.11

Correctif

5.6.12

Publication

17/07/2024

CVE-2024-5555 Moyenne · 6,4
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘social-link-title’ parameter in all versions up to, and including, 5.6.5 due to…

Versions affectées

*-5.6.5

Correctif

5.6.6

Publication

17/07/2024

CVE-2024-3925 Moyenne · 6,4
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via onclick events

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button widget in all versions up to, and including, 5.6.11…

Versions affectées

*-5.6.11

Correctif

5.6.12

Publication

11/06/2024

CVE-2024-3926 Moyenne · 6,4
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via custom_attributes

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes value in widgets in all versions up to, and including, 5.6.1…

Versions affectées

*-5.6.1

Correctif

5.6.2

Publication

21/05/2024

CVE-2024-3927 Moyenne · 5,3
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.3 – Form Submission Admin Email Bypass

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypass in all versions up to, and including, 5.6.3. This is due to…

Versions affectées

*-5.6.3

Correctif

5.6.4

Publication

21/05/2024

CVE-2024-1429 Moyenne · 6,4
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.6.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tab_link’ attribute of the Panel Slider widget in…

Versions affectées

*-5.6.0

Correctif

5.6.1

Publication

17/04/2024

CVE-2024-1426 Moyenne · 6,4
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.6.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ attribute of the Price List widget in…

Versions affectées

*-5.6.0

Correctif

5.6.1

Publication

17/04/2024

CVE-2024-2966 Moyenne · 5,3
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.5.6 – Sensitive Information Exposure via element_pack_ajax_search

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.5.6 via the element_pack_ajax_search function. This makes…

Versions affectées

*-5.5.6

Correctif

5.6.0

Publication

10/04/2024

CVE-2024-0837 Moyenne · 6,4
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image URL parameter in all versions up to,…

Versions affectées

*-5.3.2

Correctif

5.3.3

Publication

05/04/2024

CVE-2024-1428 Moyenne · 6,4
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘element_pack_wrapper_link’ attribute of the Trailer Box widget in…

Versions affectées

*-5.5.3

Correctif

5.5.4

Publication

05/04/2024

CVE-2024-30496 Critique · 9,9
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons <= 5.5.3 – Authenticated (Contributor+) SQL Injection

The Element Pack Elementor Addons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

Versions affectées

*-5.5.3

Correctif

5.5.4

Publication

28/03/2024

CVE-2024-30185 Moyenne · 6,4
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons <= 5.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via link

The Element Pack Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link URL in versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-5.5.3

Correctif

5.5.4

Publication

25/03/2024

CVE-2024-24840 Moyenne · 4,3
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Elementor Addons <= 5.4.11 – Missing Authorization via bdt_duplicate_as_draft

The Element Pack Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'bdt_duplicate_as_draft' function in versions up to, and including, 5.4.11. This makes it possible for authenticated…

Versions affectées

*-5.4.11

Correctif

5.4.12

Publication

02/02/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités