Extension WordPress
Vulnérabilités ElementInvader Addons for Elementor
Cette page rassemble les failles publiées pour ElementInvader Addons for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ElementInvader Addons for Elementor
16 fiches
ElementInvader Addons for Elementor <= 1.4.3 – Unauthenticated Stored Cross-Site Scripting
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-1.4.3
1.4.4
07/07/2026
ElementInvader Addons for Elementor <= 1.4.2 – Authenticated (Subscriber+) SQL Injection
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
*-1.4.2
1.4.3
23/03/2026
ElementInvader Addons for Elementor <= 1.4.1 – Missing Authorization
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.4.1. This makes it possible for authenticated attackers, with…
*-1.4.1
1.4.2
05/02/2026
Elementinvader Addons for Elementor <= 1.4.0 – Unauthenticated Arbitrary Email Sending
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Unauthenticated Arbitrary Email Sending in all versions up to, and including, 1.4.0. This is due to the 'elementinvader_addons_for_elementor_forms_send_form' AJAX endpoint allowing user supplied content for the email…
*-1.4.0
1.4.1
15/10/2025
ElementInvader Addons for Elementor <= 1.3.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-1.3.6
1.3.7
27/08/2025
ElementInvader Addons for Elementor <= 1.3.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-1.3.5
1.3.6
19/05/2025
ElementInvader Addons for Elementor <= 1.3.1 – Missing Authorization
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.1. This makes it possible for authenticated attackers, with…
*-1.3.1
1.3.2
24/01/2025
ElementInvader Addons for Elementor <= 1.3.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-1.3.3
1.3.4
24/01/2025
ElementInvader Addons for Elementor <= 1.3.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-1.3.0
1.3.1
24/01/2025
ElementInvader Addons for Elementor <= 1.2.6 – Authenticated (Contributor+) Local File Inclusion
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.6. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary…
*-1.2.6
1.2.7
13/01/2025
ElementInvader Addons for Elementor <= 1.3.1 – Missing Authorization to Arbitrary Options Read
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.1 via the eli_option_value shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above,…
*-1.3.1
1.3.2
11/12/2024
ElementInvader Addons for Elementor <= 1.2.9 – Authenticated (Contributor+) Information Exposure
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.9 via the Page Loader widget. This makes it possible for authenticated attackers, with contributor-level access and…
*-1.2.9
1.3.0
18/10/2024
ElementInvader Addons for Elementor <= 1.2.8 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget redirect URL in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping…
*-1.2.8
1.2.9
15/10/2024
ElementInvader Addons for Elementor <= 1.2.7 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-1.2.7
1.2.8
30/09/2024
ElementInvader Addons for Elementor <= 1.2.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-1.2.4
1.2.5
11/07/2024
ElementInvader Addons for Elementor <= 1.2.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link in the EliSlider in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This…
*-1.2.2
1.2.3
15/03/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.