Extension WordPress
Vulnérabilités Mega Elements – Addons for Elementor
Cette page rassemble les failles publiées pour Mega Elements – Addons for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Mega Elements – Addons for Elementor
6 fiches
Mega Elements – Addons for Elementor <= 1.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer Widget
The Mega Elements – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown Timer widget in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping…
*-1.3.2
1.3.3
25/09/2025
Mega Elements <= 1.2.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-1.2.6
1.2.7
21/10/2024
Mega Elements <= 1.2.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-1.2.4
1.2.5
27/09/2024
Mega Elements <= 1.2.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-1.2.2
1.2.3
01/07/2024
Mega Elements <= 1.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget
The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-1.2.1
1.2.2
14/05/2024
Mega Elements <= 1.1.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
*-1.1.9
1.2.0
16/04/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.