Extension WordPress

Vulnérabilités Elementor Website Builder – more than just a page builder, page 2

Cette page rassemble les failles publiées pour Elementor Website Builder – more than just a page builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

52Vulnérabilités
0Critiques
52Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Elementor Website Builder – more than just a page builder

52 fiches

CVE-2024-4619 Moyenne · 6,4
Elementor Website Builder – more than just a page builder

Elementor Website Builder – More than Just a Page Builder <= 3.21.5 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘hover_animation’ parameter in versions up to, and including, 3.21.5 due to insufficient input sanitization and…

Versions affectées

*-3.21.5

Correctif

3.21.6

Publication

20/05/2024

CVE-2024-2117 Moyenne · 6,4
Elementor Website Builder – more than just a page builder

Elementor Website Builder – More than Just a Page Builder <= 3.20.2 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Path Widget

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to insufficient output escaping…

Versions affectées

*-3.20.2

Correctif

3.20.3

Publication

26/03/2024

CVE-2024-24934 Élevée · 8,8
Elementor Website Builder – more than just a page builder

Elementor <= 3.19.0 – Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to arbitrary file deletions and PHAR deserialization in version up to, and including 3.19.0. This is due to the plugin not providing…

Versions affectées

*-3.19.0

Correctif

3.19.1

Publication

07/02/2024

CVE-2024-0506 Moyenne · 6,4
Elementor Website Builder – more than just a page builder

Elementor Website Builder – More than Just a Page Builder <= 3.18.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to…

Versions affectées

*-3.18.3

Correctif

3.19.0

Publication

07/02/2024

CVE-2023-48777 Élevée · 8,8
Elementor Website Builder – more than just a page builder

Elementor <= 3.18.1 – Authenticated(Contributor+) Arbitrary File Upload to Remote Code Execution via Template Import

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Remote Code Execution via file upload in all versions up to and including 3.18.1 via the template import functionality. This makes…

Versions affectées

*-3.18.1

Correctif

3.18.2

Publication

06/12/2023

CVE-2023-47504 Moyenne · 6,5
Elementor Website Builder – more than just a page builder

Elementor Website Builder <= 3.16.4 – Missing Authorization to Arbitrary Attachment Read

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_inline_svg function in all versions up to, and including, 3.16.4. This makes it possible for authenticated…

Versions affectées

*-3.16.4

Correctif

3.16.5

Publication

08/11/2023

CVE-2023-47505 Moyenne · 6,4
Elementor Website Builder – more than just a page builder

Elementor Website Builder <= 3.16.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg()

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the get_inline_svg() function in versions up to, and including, 3.16.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-3.16.4

Correctif

3.16.5

Publication

08/11/2023

CVE-2022-4953 Moyenne · 6,1
Elementor Website Builder – more than just a page builder

Elementor <= 3.5.4 – DOM-Based iFrame Injection

The Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘settings’ hash parameter in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

*-3.5.4

Correctif

3.5.5

Publication

19/07/2023

CVE-2023-33922 Moyenne · 5,4
Elementor Website Builder – more than just a page builder

Elementor <= 3.13.2 Authenticated(Contributor+) Arbitrary Post Type Creation via save_item

The Elementor plugin for WordPress is vulnerable to the creation of emergent resources due to insufficient input validation in the template "save_item" function in versions up to, and including, 3.13.3. This allows authenticated attackers, with contributor-level permissions or…

Versions affectées

[*, 3.13.3)

Correctif

3.13.3

Publication

22/05/2023

Vulnérabilité Moyenne · 5,4
Elementor Website Builder – more than just a page builder

Elementor <= 3.13.1 – Missing Authorization to Settings Update

The Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the register_as_beta_tester(), ajax_enable_safe_mode(), ajax_get_category_items(), and ajax_re_migrate_globals() functions called via AJAX actions in versions up to, and including, 3.13.1. This makes…

Versions affectées

*-3.13.1

Correctif

3.13.2

Publication

12/05/2023

CVE-2023-0329 Moyenne · 6,6
Elementor Website Builder – more than just a page builder

Elementor <= 3.12.1 – Authenticated(Administrator+) SQL Injection via 'replace_urls'

The Elementor plugin for WordPress is vulnerable to blind SQL Injection via the 'replace_urls' functionality in versions up to, and including, 3.12.1 due to insufficient escaping on the user supplied 'old' and 'new' parameters and lack of sufficient…

Versions affectées

[*, 3.12.2)

Correctif

3.12.2

Publication

24/04/2023

CVE-2022-29455 Moyenne · 6,1
Elementor Website Builder – more than just a page builder

Elementor Website Builder <= 3.5.5 – Unauthenticated DOM-based Reflected Cross-Site Scripting

The Elementor Website Builder plugin for WordPress is vulnerable to Unauthenticated DOM-based Reflected Cross-Site Scripting via the ‘videoType’ and 'onError' parameter in the lightbox module in versions up to, and including, 3.5.5 due to insufficient input sanitization and…

Versions affectées

*-3.5.5

Correctif

3.5.6

Publication

13/06/2022

CVE-2022-1329 Élevée · 8,8
Elementor Website Builder – more than just a page builder

Elementor Website Builder 3.6.0 – 3.6.2 – Missing Authorization to Remote Code Execution

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition…

Versions affectées

3.6.0-3.6.2

Correctif

3.6.3

Publication

13/04/2022

CVE-2021-24891 Moyenne · 6,1
Elementor Website Builder – more than just a page builder

Elementor Website Builder <= 3.4.7 – DOM-based Cross-Site Scripting

The Elementor Website Builder plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting via the '#elementor-action:action=lightbox&settings=' DOM in versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

0.1.0-3.4.7

Correctif

3.4.8

Publication

23/03/2021

CVE-2021-24203 Moyenne · 6,4
Elementor Website Builder – more than just a page builder

Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via html_tag

In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or…

Versions affectées

0.1.0-3.1.3

Correctif

3.1.4

Publication

17/03/2021

CVE-2021-24202 Moyenne · 6,4
Elementor Website Builder – more than just a page builder

Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via header_size

In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or…

Versions affectées

0.1.0-3.1.3

Correctif

3.1.4

Publication

17/03/2021

CVE-2021-24205 Moyenne · 6,4
Elementor Website Builder – more than just a page builder

Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via title_size Parameter

In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor…

Versions affectées

[*, 3.1.4)

Correctif

3.1.4

Publication

17/03/2021

CVE-2021-24201 Moyenne · 6,4
Elementor Website Builder – more than just a page builder

Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via html_tag

In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or…

Versions affectées

0.1.0-3.1.3

Correctif

3.1.4

Publication

17/03/2021

CVE-2021-24206 Moyenne · 6,4
Elementor Website Builder – more than just a page builder

Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via title_size

In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor…

Versions affectées

0.1.0-3.1.3

Correctif

3.1.4

Publication

17/03/2021

CVE-2021-24204 Moyenne · 6,4
Elementor Website Builder – more than just a page builder

Elementor Website Builder <= 3.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via title_html_tag

In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or…

Versions affectées

*-3.1.3

Correctif

3.1.4

Publication

17/03/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités