Extension WordPress

Vulnérabilités Royal Addons for Elementor – Addons and Templates Kit for Elementor, page 3

Cette page rassemble les failles publiées pour Royal Addons for Elementor – Addons and Templates Kit for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

82Vulnérabilités
1Critiques
82Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Royal Addons for Elementor – Addons and Templates Kit for Elementor

82 fiches

CVE-2024-5818 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.980 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugin's Magazine Grid/Slider widget in all versions up to, and including, 1.3.980 due to insufficient input sanitization and output escaping…

Versions affectées

*-1.3.980

Correctif

1.3.981

Publication

23/07/2024

CVE-2024-4488 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.976 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list’ parameter in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.3.976

Correctif

1.3.977

Publication

06/06/2024

CVE-2024-4489 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.976 – Authenticated (Author+) Stored Cross-Site Scripting via SVG Uploads

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-1.3.976

Correctif

1.3.977

Publication

06/06/2024

CVE-2024-4087 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.975 – Authenticated (Contributor+) Stored Cross-Site Scripting via Back to Top Widget

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back to Top widget in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping…

Versions affectées

*-1.3.975

Correctif

1.3.976

Publication

31/05/2024

CVE-2024-4342 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.975 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, and product mini cart widgets in all versions up to, and including, 1.3.975…

Versions affectées

*-1.3.975

Correctif

1.3.976

Publication

31/05/2024

CVE-2024-3887 Moyenne · 5,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.974 – Authenticated (Contributor+) Stored Cross-Site Scripting via Form Builder Widget

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder widget in all versions up to, and including, 1.3.974 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-1.3.974

Correctif

1.3.975

Publication

15/05/2024

CVE-2024-2798 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.971 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget containers in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-1.3.971

Correctif

1.3.972

Publication

22/04/2024

CVE-2024-3675 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.971 – Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flip Carousel, Flip Box, Post Grid, and Taxonomy List widgets in all versions up to, and including, 1.3.971 due to…

Versions affectées

*-1.3.971

Correctif

1.3.972

Publication

22/04/2024

CVE-2024-32786 Moyenne · 5,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons <= 1.3.93 – Unauthenticated IP Spoofing

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.3.93 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to spoof…

Versions affectées

*-1.3.93

Correctif

1.3.95

Publication

22/04/2024

CVE-2024-3889 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.971 – Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Accordion widget in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on…

Versions affectées

*-1.3.971

Correctif

1.3.972

Publication

22/04/2024

CVE-2024-2799 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.971 – Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid & Advanced Text widget HTML tags in all versions up to, and including, 1.3.96 due to insufficient input sanitization…

Versions affectées

*-1.3.971

Correctif

1.3.972

Publication

22/04/2024

CVE-2024-1567 Élevée · 8,2
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.94 – Unauthenticated Limited File Upload

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for…

Versions affectées

*-1.3.94

Correctif

1.3.95

Publication

19/04/2024

CVE-2024-31236 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons <= 1.3.93 – Authenticated (Contributor+) Stored Cross-Site Scriting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

Versions affectées

*-1.3.93

Correctif

1.3.95

Publication

05/04/2024

CVE-2024-1500 Moyenne · 5,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.91 – Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo Widget in all versions up to, and including, 1.3.91 due to insufficient input sanitization and output escaping on user supplied…

Versions affectées

*-1.3.91

Correctif

1.3.92

Publication

06/03/2024

CVE-2024-0442 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.87 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element URL parameters in all versions up to, and including, 1.3.87 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.3.87

Correctif

1.3.88

Publication

08/02/2024

CVE-2024-0511 Moyenne · 4,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.87 – Cross-Site Request Forgery via wpr_update_form_action_meta

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the wpr_update_form_action_meta function. This makes…

Versions affectées

*-1.3.87

Correctif

1.3.88

Publication

07/02/2024

CVE-2024-0516 Moyenne · 5,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.87 – Missing Authorization via wpr_update_form_action_meta

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta function in all versions up to, and including, 1.3.87. This makes it possible…

Versions affectées

*-1.3.87

Correctif

1.3.88

Publication

07/02/2024

CVE-2024-0512 Moyenne · 4,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.87 – Cross-Site Request Forgery via add_to_wishlist

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_wishlist function. This makes…

Versions affectées

*-1.3.87

Correctif

1.3.88

Publication

07/02/2024

CVE-2024-0514 Moyenne · 4,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.87 – Cross-Site Request Forgery via add_to_compare

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_compare function. This makes…

Versions affectées

*-1.3.87

Correctif

1.3.88

Publication

07/02/2024

CVE-2024-0515 Moyenne · 4,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.87 – Cross-Site Request Forgery via remove_from_compare

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_compare function. This makes…

Versions affectées

*-1.3.87

Correctif

1.3.88

Publication

07/02/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités