Extension WordPress

Vulnérabilités Consulting Elementor Widgets

Cette page rassemble les failles publiées pour Consulting Elementor Widgets, leurs plages de versions affectées et les correctifs signalés dans la base locale.

6Vulnérabilités
2Critiques
6Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Consulting Elementor Widgets

6 fiches

CVE-2025-64361 Moyenne · 6,4
Consulting Elementor Widgets

Consulting Elementor Widgets <= 1.4.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Consulting Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-1.4.2

Correctif

1.4.3

Publication

27/10/2025

CVE-2025-64360 Élevée · 7,5
Consulting Elementor Widgets

Consulting Elementor Widgets <= 1.4.2 – Authenticated (Contributor+) Local File Inclusion

The Consulting Elementor Widgets plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.2. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files…

Versions affectées

*-1.4.2

Correctif

1.4.3

Publication

27/10/2025

CVE-2024-37091 Élevée · 8,8
Consulting Elementor Widgets

Consulting Elementor Widgets <= 1.3.0 – Authenticated (Contributor+) Remote Code Execution

The Consulting Elementor Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.0. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the…

Versions affectées

*-1.3.0

Correctif

1.3.1

Publication

20/06/2024

CVE-2024-37092 Élevée · 8,8
Consulting Elementor Widgets

Consulting Elementor Widgets <= 1.3.0 – Authenticated (Contributor+) Local File Inclusion

The Consulting Elementor Widgets plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.0. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary…

Versions affectées

*-1.3.0

Correctif

1.3.1

Publication

20/06/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités