Extension WordPress

Vulnérabilités ElementInvader Addons for Elementor

Cette page rassemble les failles publiées pour ElementInvader Addons for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

16Vulnérabilités
0Critiques
16Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de ElementInvader Addons for Elementor

16 fiches

CVE-2026-57376 Élevée · 7,2
ElementInvader Addons for Elementor

ElementInvader Addons for Elementor <= 1.4.3 – Unauthenticated Stored Cross-Site Scripting

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

Versions affectées

*-1.4.3

Correctif

1.4.4

Publication

07/07/2026

CVE-2026-25007 Moyenne · 6,5
ElementInvader Addons for Elementor

ElementInvader Addons for Elementor <= 1.4.2 – Authenticated (Subscriber+) SQL Injection

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

Versions affectées

*-1.4.2

Correctif

1.4.3

Publication

23/03/2026

CVE-2025-10873 Moyenne · 5,8
ElementInvader Addons for Elementor

Elementinvader Addons for Elementor <= 1.4.0 – Unauthenticated Arbitrary Email Sending

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Unauthenticated Arbitrary Email Sending in all versions up to, and including, 1.4.0. This is due to the 'elementinvader_addons_for_elementor_forms_send_form' AJAX endpoint allowing user supplied content for the email…

Versions affectées

*-1.4.0

Correctif

1.4.1

Publication

15/10/2025

CVE-2025-58205 Moyenne · 6,4
ElementInvader Addons for Elementor

ElementInvader Addons for Elementor <= 1.3.6 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-1.3.6

Correctif

1.3.7

Publication

27/08/2025

CVE-2025-48288 Moyenne · 6,4
ElementInvader Addons for Elementor

ElementInvader Addons for Elementor <= 1.3.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-1.3.5

Correctif

1.3.6

Publication

19/05/2025

CVE-2025-24729 Moyenne · 6,4
ElementInvader Addons for Elementor

ElementInvader Addons for Elementor <= 1.3.3 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-1.3.3

Correctif

1.3.4

Publication

24/01/2025

CVE-2025-24578 Moyenne · 6,4
ElementInvader Addons for Elementor

ElementInvader Addons for Elementor <= 1.3.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-1.3.0

Correctif

1.3.1

Publication

24/01/2025

CVE-2025-22786 Élevée · 8,8
ElementInvader Addons for Elementor

ElementInvader Addons for Elementor <= 1.2.6 – Authenticated (Contributor+) Local File Inclusion

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.6. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary…

Versions affectées

*-1.2.6

Correctif

1.2.7

Publication

13/01/2025

CVE-2024-12059 Moyenne · 4,3
ElementInvader Addons for Elementor

ElementInvader Addons for Elementor <= 1.3.1 – Missing Authorization to Arbitrary Options Read

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.1 via the eli_option_value shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above,…

Versions affectées

*-1.3.1

Correctif

1.3.2

Publication

11/12/2024

CVE-2024-9889 Moyenne · 4,3
ElementInvader Addons for Elementor

ElementInvader Addons for Elementor <= 1.2.9 – Authenticated (Contributor+) Information Exposure

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.9 via the Page Loader widget. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-1.2.9

Correctif

1.3.0

Publication

18/10/2024

CVE-2024-9888 Moyenne · 5,4
ElementInvader Addons for Elementor

ElementInvader Addons for Elementor <= 1.2.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget redirect URL in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping…

Versions affectées

*-1.2.8

Correctif

1.2.9

Publication

15/10/2024

CVE-2024-47630 Moyenne · 6,4
ElementInvader Addons for Elementor

ElementInvader Addons for Elementor <= 1.2.7 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-1.2.7

Correctif

1.2.8

Publication

30/09/2024

CVE-2024-38705 Moyenne · 6,4
ElementInvader Addons for Elementor

ElementInvader Addons for Elementor <= 1.2.4 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-1.2.4

Correctif

1.2.5

Publication

11/07/2024

CVE-2024-2308 Moyenne · 6,4
ElementInvader Addons for Elementor

ElementInvader Addons for Elementor <= 1.2.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link in the EliSlider in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-1.2.2

Correctif

1.2.3

Publication

15/03/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités