Extension WordPress
Vulnérabilités ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
Cette page rassemble les failles publiées pour ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
26 fiches
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor <= 3.9.6 – Missing Authorization
The ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.6. This makes…
*-3.9.6
3.9.7
27/05/2026
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor <= 3.9.6 – Missing Authorization
The ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.6. This makes…
*-3.9.6
3.9.7
27/05/2026
ElementsKit Elementor Addons <= 3.8.2 – Missing Authorization to Unauthenticated Widget Content Overwrite
The ElementsKit Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `Live_Action::reset()` function in all versions up to, and including, 3.8.2 The function is hooked to the…
*-3.8.2
3.9.0
04/05/2026
ElementsKit Elementor Addons and Templates <= 3.7.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Simple Tab Widget
The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ekit_tab_title' parameter in the Simple Tab widget in all versions up to, and including, 3.7.9 due to insufficient input sanitization and…
*-3.7.9
3.8.0
03/04/2026
ElementsKit Elementor addons Lite < 3.7.9 – Missing Authorization
The ElementsKit Elementor addons Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 3.7.9. This makes it possible for unauthenticated attackers to perform an unauthorized…
[*, 3.7.9)
3.7.9
24/02/2026
ElementsKit Elementor Addons and Templates <= 3.5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget
The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom widget in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output…
*-3.5.2
3.5.3
24/07/2025
ElementsKit Lite <= 3.5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget
The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin image comparison widget's before/after labels in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output…
*-3.5.2
3.5.3
18/06/2025
ElementsKit Elementor addons <= 3.4.7 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes…
*-3.4.7
3.4.8
28/03/2025
ElementsKit Elementor addons <= 3.4.0 – Unauthenticated Information Exposure via get_megamenu_content Function
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function. This makes it possible for unauthenticated attackers…
*-3.4.0
3.4.1
18/02/2025
ElementsKit Elementor addons <= 3.4.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping on user supplied…
*-3.4.0
3.4.1
14/02/2025
ElementsKit Elementor addons <= 3.2.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-3.2.9
3.3.0
25/10/2024
ElementsKit Elementor addons <= 3.2.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-3.2.7
3.2.8
25/09/2024
ElementsKit Elementor addons <= 3.2.0 – Unauthenticated Information Exposure via ekit_widgetarea_content Function
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view…
*-3.2.0
3.2.1
18/07/2024
Elements kit Elementor addons <= 3.1.4 – Missing Authorization
The Elements kit Elementor addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor() function in versions up to, and including, 3.1.4. This makes it possible for unauthenticated…
*-3.1.4
3.2.0
27/06/2024
ElementsKit Elementor addons 3.0.7 – 3.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions 3.0.7 through 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
3.0.7-3.1.2
3.1.3
30/04/2024
ElementsKit Elementor addons <= 3.1.0 – Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Module
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the generate_navigation_markup function of the Onepage Scroll module. This makes it possible for authenticated attackers, with…
*-3.1.0
3.1.1
22/04/2024
ElementsKit Elementor addons Lite <= 3.0.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ElementsKit Elementor addons Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-3.0.6
3.0.7
15/04/2024
ElementsKit Elementor addons <= 3.0.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-3.0.7
3.1.0
03/04/2024
ElementsKit Elementor addons <= 3.0.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button ID parameter in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible…
*-3.0.6
3.0.7
29/03/2024
ElementsKit Elementor addons <= 3.0.6 – Authenticated (Contributor+) Local File Inclusion in render_raw
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the render_raw function. This makes it possible for authenticated attackers, with contributor-level access and above, to…
*-3.0.6
3.0.7
29/03/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.