Extension WordPress
Vulnérabilités Elementor Website Builder – more than just a page builder, page 2
Cette page rassemble les failles publiées pour Elementor Website Builder – more than just a page builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Elementor Website Builder – more than just a page builder
52 fiches
Elementor Website Builder – More than Just a Page Builder <= 3.21.5 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘hover_animation’ parameter in versions up to, and including, 3.21.5 due to insufficient input sanitization and…
*-3.21.5
3.21.6
20/05/2024
Elementor Website Builder – More than Just a Page Builder <= 3.20.2 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Path Widget
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to insufficient output escaping…
*-3.20.2
3.20.3
26/03/2024
Elementor <= 3.19.0 – Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to arbitrary file deletions and PHAR deserialization in version up to, and including 3.19.0. This is due to the plugin not providing…
*-3.19.0
3.19.1
07/02/2024
Elementor Website Builder – More than Just a Page Builder <= 3.18.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to…
*-3.18.3
3.19.0
07/02/2024
Elementor <= 3.18.1 – Authenticated(Contributor+) Arbitrary File Upload to Remote Code Execution via Template Import
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Remote Code Execution via file upload in all versions up to and including 3.18.1 via the template import functionality. This makes…
*-3.18.1
3.18.2
06/12/2023
Elementor Website Builder <= 3.16.4 – Missing Authorization to Arbitrary Attachment Read
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_inline_svg function in all versions up to, and including, 3.16.4. This makes it possible for authenticated…
*-3.16.4
3.16.5
08/11/2023
Elementor Website Builder <= 3.16.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg()
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the get_inline_svg() function in versions up to, and including, 3.16.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-3.16.4
3.16.5
08/11/2023
Elementor <= 3.5.4 – DOM-Based iFrame Injection
The Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘settings’ hash parameter in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-3.5.4
3.5.5
19/07/2023
Elementor <= 3.13.2 Authenticated(Contributor+) Arbitrary Post Type Creation via save_item
The Elementor plugin for WordPress is vulnerable to the creation of emergent resources due to insufficient input validation in the template "save_item" function in versions up to, and including, 3.13.3. This allows authenticated attackers, with contributor-level permissions or…
[*, 3.13.3)
3.13.3
22/05/2023
Elementor <= 3.13.1 – Missing Authorization to Settings Update
The Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the register_as_beta_tester(), ajax_enable_safe_mode(), ajax_get_category_items(), and ajax_re_migrate_globals() functions called via AJAX actions in versions up to, and including, 3.13.1. This makes…
*-3.13.1
3.13.2
12/05/2023
Elementor <= 3.12.1 – Authenticated(Administrator+) SQL Injection via 'replace_urls'
The Elementor plugin for WordPress is vulnerable to blind SQL Injection via the 'replace_urls' functionality in versions up to, and including, 3.12.1 due to insufficient escaping on the user supplied 'old' and 'new' parameters and lack of sufficient…
[*, 3.12.2)
3.12.2
24/04/2023
Elementor Website Builder <= 3.5.5 – Unauthenticated DOM-based Reflected Cross-Site Scripting
The Elementor Website Builder plugin for WordPress is vulnerable to Unauthenticated DOM-based Reflected Cross-Site Scripting via the ‘videoType’ and 'onError' parameter in the lightbox module in versions up to, and including, 3.5.5 due to insufficient input sanitization and…
*-3.5.5
3.5.6
13/06/2022
Elementor Website Builder 3.6.0 – 3.6.2 – Missing Authorization to Remote Code Execution
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition…
3.6.0-3.6.2
3.6.3
13/04/2022
Elementor Website Builder <= 3.4.7 – DOM-based Cross-Site Scripting
The Elementor Website Builder plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting via the '#elementor-action:action=lightbox&settings=' DOM in versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
0.1.0-3.4.7
3.4.8
23/03/2021
Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via html_tag
In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or…
0.1.0-3.1.3
3.1.4
17/03/2021
Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via header_size
In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or…
0.1.0-3.1.3
3.1.4
17/03/2021
Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via title_size Parameter
In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor…
[*, 3.1.4)
3.1.4
17/03/2021
Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via html_tag
In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or…
0.1.0-3.1.3
3.1.4
17/03/2021
Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via title_size
In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor…
0.1.0-3.1.3
3.1.4
17/03/2021
Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via title_html_tag
In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or…
*-3.1.3
3.1.4
17/03/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.