Extension WordPress

Vulnérabilités PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

Cette page rassemble les failles publiées pour PowerPack Addons for Elementor (Free Widgets, Extensions and Templates), leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
0Critiques
13Avec correctif
6,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

13 fiches

CVE-2026-32430 Moyenne · 6,4
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

PowerPack Addons for Elementor <= 2.9.9 – Authenticated (Contributor+) Stored Cross-Site Scripting

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-2.9.9

Correctif

2.9.10

Publication

01/03/2026

CVE-2025-8388 Moyenne · 6,4
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

PowerPack Lite for Elementor <= 2.9.4 – Authenticated (Contributor+) Stored Cross-Site Scripting Via 'cursor_url'

The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor_url’ parameter in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping.…

Versions affectées

*-2.9.4

Correctif

2.9.5

Publication

09/09/2025

CVE-2025-1512 Moyenne · 6,4
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) <= 2.9.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Cursor Extension in all versions up to, and including, 2.9.0 due to insufficient input sanitization and output…

Versions affectées

*-2.9.0

Correctif

2.9.1

Publication

31/03/2025

CVE-2024-10692 Moyenne · 4,3
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) <= 2.8.1 – Authenticated (Contributor+) Post Disclosure

The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 via the Content Reveal widget due to insufficient restrictions on which posts can…

Versions affectées

*-2.8.1

Correctif

2.8.2

Publication

05/12/2024

CVE-2024-5787 Moyenne · 6,4
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) <= 2.7.20 – Authenticated (Contributor+) Stored Cross-Site Scripting via Link Effects Widget

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's Link Effects widget in all versions up to, and including, 2.7.20 due…

Versions affectées

*-2.7.20

Correctif

2.7.21

Publication

12/06/2024

CVE-2024-5327 Moyenne · 6,4
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) <= 2.7.19 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘pp_animated_gradient_bg_color’ parameter in all versions up to, and including, 2.7.19 due to insufficient input sanitization and…

Versions affectées

*-2.7.19

Correctif

2.7.20

Publication

29/05/2024

CVE-2024-2492 Moyenne · 6,4
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

PowerPack Addons for Elementor <= 2.7.18 – Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Tweet Widget

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Tweet widget in all versions up to, and including, 2.7.18 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.7.18

Correctif

2.7.19

Publication

29/03/2024

CVE-2024-2491 Moyenne · 6,4
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

PowerPack Addons for Elementor <= 2.7.17 – Authenticated (Contributor+) Stored Cross-Site Scripting via *_html_tag*

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the *_html_tag* attribute of multiple widgets in all versions up to, and including, 2.7.17 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-2.7.17

Correctif

2.7.18

Publication

29/03/2024

CVE-2024-1411 Moyenne · 6,4
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

PowerPack Addons for Elementor <= 2.7.15 – Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Buttons Widget

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the settings of the Twitter Buttons Widget in all versions up to, and including, 2.7.15 due to insufficient input sanitization and output escaping.…

Versions affectées

*-2.7.15

Correctif

2.7.16

Publication

15/02/2024

CVE-2024-1055 Moyenne · 5,4
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) <= 2.7.14 – Authenticated (Contributor+) Stored Cross-Site Scripting

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's buttons in all versions up to, and including, 2.7.14 due to insufficient input sanitization and output…

Versions affectées

*-2.7.14

Correctif

2.7.15

Publication

06/02/2024

CVE-2023-6984 Moyenne · 5,3
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) <= 2.7.13 – Cross-Site Request Forgery

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.13. This is due to missing or incorrect nonce validation in the…

Versions affectées

*-2.7.13

Correctif

2.7.14

Publication

02/01/2024

CVE-2021-24263 Moyenne · 5,4
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)

PowerPack Addons for Elementor <= 2.3.1 – Contributor+ Stored Cross-Site Scripting

The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

Versions affectées

*-2.3.1

Correctif

2.3.2

Publication

13/04/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités