Extension WordPress
Vulnérabilités Cowidgets – Elementor Addons
Cette page rassemble les failles publiées pour Cowidgets – Elementor Addons, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Cowidgets – Elementor Addons
5 fiches
Cowidgets – Elementor Addons <= 1.2.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-1.2.0
Non indiqué
28/11/2024
Cowidgets – Elementor Addons <= 1.2.0 – Authenticated (Contributor+) Post Disclosure
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.0 via the 'ce_template' shortcode due to insufficient restrictions on which posts can be included. This makes it…
*-1.2.0
Non indiqué
08/11/2024
Cowidgets – Elementor Addons <= 1.2.0 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.2.0
Non indiqué
08/11/2024
Cowidgets – Elementor Addons <= 1.1.2 – Authenticated (Contributor+) Local File Inclusion
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.2 via the 'item_style' and 'style' parameters. This makes it possible for authenticated attackers, with Contributor-level access…
*-1.1.2
1.2.0
05/06/2024
Cowidgets – Elementor Addons <= 1.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via heading_tag Parameter
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_tag’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.1.2
1.2.0
03/06/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.