Extension WordPress
Vulnérabilités PowerPack Pro for Elementor
Cette page rassemble les failles publiées pour PowerPack Pro for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de PowerPack Pro for Elementor
6 fiches
PowerPack Pro for Elementor < v2.13.0 – Missing Authorization
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to v2.13.0 (exclusive). This makes it possible for unauthenticated attackers to perform…
[*, v2.13.0)
2.13.0
29/04/2026
PowerPack Pro for Elementor <= 2.10.14 – Authenticated (Contributor+) Privilege Escalation
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.10.14. This is due to plugin not properly restricting who can set roles on the user registration form.…
*-2.10.14
2.10.15
24/07/2024
PowerPack Pro for Elementor <= 2.10.17 – Authenticated (Contributor+) Privilege Escalation
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for…
*-2.10.17
2.10.18
07/06/2024
PowerPack Pro for Elementor <= 2.10.6 – Missing Authorization to Settings Reset
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in all versions up to, and including, 2.10.6. This makes it possible for unauthenticated attackers to reset…
*-2.10.6
2.10.8
02/02/2024
PowerPack Pro for Elementor < 2.10.8 – Cross-Site Request Forgery to Plugin Settings Modification and Cross-Site Scripting
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions prior to 2.10.8. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to modify plugin…
[*, 2.10.8)
2.10.8
02/02/2024
PowerPack Pro for Elementor <= 2.9.23 – Reflected Cross-Site Scripting
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-2.9.23
2.9.24
01/12/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.