Extension WordPress
Vulnérabilités ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor, page 2
Cette page rassemble les failles publiées pour ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
26 fiches
ElementsKit Elementor addons <= 3.0.3 – Authenticated(Editor+) Stored Cross-Site Scripting
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar element attributes in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it…
*-3.0.3
3.0.4
15/03/2024
ElementsKit Elementor addons <= 3.0.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it possible…
*-3.0.5
3.0.6
15/03/2024
ElementsKit Elementor addons <= 3.0.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blog post read more button in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes…
*-3.0.4
3.0.5
15/03/2024
ElementsKit Lite <= 3.0.3 – Unauthenticated Sensitive Information Exposure
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to obtain contents of posts in…
*-3.0.3
3.0.4
08/01/2024
Elements kit Elementor addons <= 2.9.1 – Missing Authorization
The Elements kit Elementor addons plugin for WordPress is vulnerable to unauthorized admin notice dismissal due to a missing capability check on the dismiss_ajax_call function in versions up to, and including, 2.9.0. This makes it possible for authenticated…
*-2.9.1
2.9.2
23/08/2023
Elements Kit Lite/Pro <= 2.1.7 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
*-2.1.7
2.2.0
13/04/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.