Extension WordPress

Vulnérabilités Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits, page 2

Cette page rassemble les failles publiées pour Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits, leurs plages de versions affectées et les correctifs signalés dans la base locale.

28Vulnérabilités
0Critiques
28Avec correctif
7,3CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

28 fiches

CVE-2024-33595 Moyenne · 4,3
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

Master Addons for Elementor <= 2.0.5.4.1 – Missing Authorization on Duplicate Post

The Master Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the jltma_duplicator_row_actions() function in versions up to, and including, 2.0.5.4.1. This makes it possible for authenticated…

Versions affectées

*-2.0.5.4.1

Correctif

2.0.5.6

Publication

25/04/2024

CVE-2024-2139 Moyenne · 6,4
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

Master Addons for Elementor <= 2.0.5.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget

The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in all versions up to, and including, 2.0.5.6 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.0.5.6

Correctif

2.0.5.7

Publication

26/03/2024

CVE-2024-29911 Moyenne · 6,4
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

Master Addons for Elementor <= 2.0.5.4.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.5.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-2.0.5.4.1

Correctif

2.0.5.6

Publication

25/03/2024

Vulnérabilité Moyenne · 6,4
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

Master Addons for Elementor <= 2.0.3 – Authenticated(Contributor+) Stored Cross-Site Scripting

The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the heading tag dropdown in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.0.3

Correctif

2.0.4

Publication

11/10/2023

CVE-2023-40679 Élevée · 7,3
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

Master Addons for Elementor <= 2.0.5.3 – Missing Authorization

The Master Addons for Elementor plugin for WordPress is vulnerable to unauthorized functionality access due to a missing capability check on the jltma_rest_api_action REST API action in versions up to, and including, 2.0.5.3. This makes it possible for…

Versions affectées

*-2.0.5.3

Correctif

2.0.5.4.1

Publication

22/08/2023

CVE-2023-33999 Moyenne · 6,1
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

1.0.6-2.0.2

Correctif

2.0.3

Publication

18/07/2023

CVE-2022-4974 Moyenne · 6,3
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

Freemius SDK <= 2.4.2 – Missing Authorization Checks

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…

Versions affectées

[*, 1.8.5)

Correctif

1.8.5

Publication

04/03/2022

CVE-2022-0327 Moyenne · 6,1
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

Master Addons for Elementor <= 1.8.1 – Reflected Cross-Site Scripting

The Master Addons for Elementor WordPress plugin before 1.8.5 does not sanitise and escape the error_message parameter before outputting it back in the response of the jltma_restrict_content AJAX action, available to unauthenticated and authenticated users, leading to a…

Versions affectées

[*, 1.8.5)

Correctif

1.8.5

Publication

21/02/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités