Extension WordPress

Vulnérabilités Essential Addons for Elementor – Popular Elementor Templates & Widgets, page 3

Cette page rassemble les failles publiées pour Essential Addons for Elementor – Popular Elementor Templates & Widgets, leurs plages de versions affectées et les correctifs signalés dans la base locale.

64Vulnérabilités
2Critiques
64Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Essential Addons for Elementor – Popular Elementor Templates & Widgets

64 fiches

CVE-2024-3733 Moyenne · 5,3
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 – Information Exposure

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery()…

Versions affectées

*-5.9.15

Correctif

5.9.16

Publication

24/04/2024

CVE-2024-3333 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 5.9.14 – Authenticated (Contributor+) Store Cross-Site Scripting via Widget URL Attribute

The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attributes of widgets in all versions up to, and including, 5.9.14 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-5.9.14

Correctif

5.9.15

Publication

16/04/2024

CVE-2024-2974 Moyenne · 5,3
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 – Unauthenticated Sensitive Information Exposure

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated…

Versions affectées

*-5.9.13

Correctif

5.9.14

Publication

29/03/2024

CVE-2024-3018 Élevée · 8,8
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 5.9.13 – Authenticated (Author+) PHP Object Injection via error_resetpassword

The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the "Login | Register Form" widget…

Versions affectées

*-5.9.13

Correctif

5.9.14

Publication

29/03/2024

CVE-2024-2623 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's message parameter in all versions up to, and including, 5.9.11 due…

Versions affectées

*-5.9.11

Correctif

5.9.12

Publication

25/03/2024

CVE-2024-2650 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the alignment parameter in the Woo Product Carousel widget in all versions up to,…

Versions affectées

*-5.9.11

Correctif

5.9.12

Publication

25/03/2024

CVE-2024-1537 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Data Table widget in all versions up to, and including, 5.9.9 due…

Versions affectées

*-5.9.9

Correctif

5.9.10

Publication

11/03/2024

CVE-2024-1536 Élevée · 7,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's event calendar widget in all versions up to, and including, 5.9.9 due…

Versions affectées

*-5.9.9

Correctif

5.9.10

Publication

11/03/2024

CVE-2024-1276 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Content Ticker arrow attribute in all versions up to, and including, 5.9.8 due…

Versions affectées

*-5.9.8

Correctif

5.9.9

Publication

12/02/2024

CVE-2024-1171 Moyenne · 5,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery Widget in all versions up to, and including, 5.9.8 due…

Versions affectées

*-5.9.8

Correctif

5.9.9

Publication

12/02/2024

CVE-2024-1172 Moyenne · 5,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion widget in all versions up to, and including, 5.9.8 due to…

Versions affectées

*-5.9.8

Correctif

5.9.9

Publication

12/02/2024

CVE-2024-1236 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Filterable Controls label icon parameter in all versions up to, and including, 5.9.8…

Versions affectées

*-5.9.8

Correctif

5.9.9

Publication

12/02/2024

CVE-2024-0954 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting through editing context via the 'data-eael-wrapper-link' wrapper in all versions up to, and including, 5.9.7…

Versions affectées

*-5.9.7

Correctif

5.9.8

Publication

01/02/2024

CVE-2024-0586 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 – Authenticated (Contributor+) Stored Cross-Site Scritping

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Login/Register Element in all versions up to, and including, 5.9.4 due to insufficient…

Versions affectées

*-5.9.4

Correctif

5.9.5

Publication

17/01/2024

CVE-2024-0585 Moyenne · 5,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 5.9.4 due…

Versions affectées

*-5.9.4

Correctif

5.9.5

Publication

17/01/2024

CVE-2023-7044 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ID in all versions up to, and including, 5.9.2 due to insufficient input…

Versions affectées

*-5.9.2

Correctif

5.9.3

Publication

03/01/2024

CVE-2023-41955 Élevée · 8,8
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 5.8.8 – Authenticated (Contributor+) Privilege Escalation

The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 5.8.8 due to a lack of restrictions on who can add a registration form and a custom registration role…

Versions affectées

*-5.8.8

Correctif

5.8.9

Publication

14/09/2023

CVE-2023-3779 Moyenne · 5,3
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons For Elementor <=5.8.1 – Unauthenticated MailChimp API Key Disclosure

The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 due to the plugin adding the API key to the source code of any page running…

Versions affectées

*-5.8.1

Correctif

5.8.2

Publication

19/07/2023

CVE-2023-32243 Critique · 9,8
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 5.7.1 – Unauthenticated Arbitrary Password Reset to Privilege Escalation

The Essential Addons for Elementor plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Privilege Escalation in versions up to, and including, 5.7.1. This is due to a lack of validation of a password reset key…

Versions affectées

*-5.7.1

Correctif

5.7.2

Publication

11/05/2023

CVE-2022-0683 Moyenne · 6,1
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor Lite <= 5.0.8 – Reflected Cross-Site Scripting

The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the settings parameter found in the ~/includes/Traits/Helper.php file which allows attackers to inject arbitrary web scripts onto a…

Versions affectées

*-5.0.8

Correctif

5.0.9

Publication

18/02/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités