Extension WordPress

Vulnérabilités Essential Addons for Elementor – Popular Elementor Templates & Widgets, page 3

Cette page rassemble les failles publiées pour Essential Addons for Elementor – Popular Elementor Templates & Widgets, leurs plages de versions affectées et les correctifs signalés dans la base locale.

68Vulnérabilités
2Critiques
68Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Essential Addons for Elementor – Popular Elementor Templates & Widgets

68 fiches

CVE-2024-4449 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 5.9.19 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Several Widgets

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Fancy Text', 'Filter Gallery', 'Sticky Video', 'Content Ticker', 'Woo Product Gallery', &…

Versions affectées

*-5.9.19

Correctif

5.9.20

Publication

09/05/2024

CVE-2024-4156 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_event_text_color’ parameter in versions up to, and including, 5.9.17 due to insufficient input…

Versions affectées

*-5.9.17

Correctif

5.9.18

Publication

30/04/2024

CVE-2024-3728 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 – Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery & Interactive Circle widgets in all versions up to, and…

Versions affectées

*-5.9.15

Correctif

5.9.16

Publication

24/04/2024

CVE-2024-4003 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_team_members_image_rounded parameter in the Team Members widget in all versions up to, and…

Versions affectées

*-5.9.15

Correctif

5.9.16

Publication

24/04/2024

CVE-2024-3733 Moyenne · 5,3
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 – Information Exposure

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery()…

Versions affectées

*-5.9.15

Correctif

5.9.16

Publication

24/04/2024

CVE-2024-3333 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 5.9.14 – Authenticated (Contributor+) Store Cross-Site Scripting via Widget URL Attribute

The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attributes of widgets in all versions up to, and including, 5.9.14 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-5.9.14

Correctif

5.9.15

Publication

16/04/2024

CVE-2024-2974 Moyenne · 5,3
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 – Unauthenticated Sensitive Information Exposure

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated…

Versions affectées

*-5.9.13

Correctif

5.9.14

Publication

29/03/2024

CVE-2024-3018 Élevée · 8,8
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 5.9.13 – Authenticated (Author+) PHP Object Injection via error_resetpassword

The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the "Login | Register Form" widget…

Versions affectées

*-5.9.13

Correctif

5.9.14

Publication

29/03/2024

CVE-2024-2623 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's message parameter in all versions up to, and including, 5.9.11 due…

Versions affectées

*-5.9.11

Correctif

5.9.12

Publication

25/03/2024

CVE-2024-2650 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the alignment parameter in the Woo Product Carousel widget in all versions up to,…

Versions affectées

*-5.9.11

Correctif

5.9.12

Publication

25/03/2024

CVE-2024-1537 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Data Table widget in all versions up to, and including, 5.9.9 due…

Versions affectées

*-5.9.9

Correctif

5.9.10

Publication

11/03/2024

CVE-2024-1536 Élevée · 7,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's event calendar widget in all versions up to, and including, 5.9.9 due…

Versions affectées

*-5.9.9

Correctif

5.9.10

Publication

11/03/2024

CVE-2024-1276 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Content Ticker arrow attribute in all versions up to, and including, 5.9.8 due…

Versions affectées

*-5.9.8

Correctif

5.9.9

Publication

12/02/2024

CVE-2024-1171 Moyenne · 5,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery Widget in all versions up to, and including, 5.9.8 due…

Versions affectées

*-5.9.8

Correctif

5.9.9

Publication

12/02/2024

CVE-2024-1172 Moyenne · 5,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion widget in all versions up to, and including, 5.9.8 due to…

Versions affectées

*-5.9.8

Correctif

5.9.9

Publication

12/02/2024

CVE-2024-1236 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Filterable Controls label icon parameter in all versions up to, and including, 5.9.8…

Versions affectées

*-5.9.8

Correctif

5.9.9

Publication

12/02/2024

CVE-2024-0954 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting through editing context via the 'data-eael-wrapper-link' wrapper in all versions up to, and including, 5.9.7…

Versions affectées

*-5.9.7

Correctif

5.9.8

Publication

01/02/2024

CVE-2024-0586 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 – Authenticated (Contributor+) Stored Cross-Site Scritping

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Login/Register Element in all versions up to, and including, 5.9.4 due to insufficient…

Versions affectées

*-5.9.4

Correctif

5.9.5

Publication

17/01/2024

CVE-2024-0585 Moyenne · 5,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 5.9.4 due…

Versions affectées

*-5.9.4

Correctif

5.9.5

Publication

17/01/2024

CVE-2023-7044 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ID in all versions up to, and including, 5.9.2 due to insufficient input…

Versions affectées

*-5.9.2

Correctif

5.9.3

Publication

03/01/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités