Extension WordPress

Vulnérabilités The Pack Elementor addon

Cette page rassemble les failles publiées pour The Pack Elementor addon, leurs plages de versions affectées et les correctifs signalés dans la base locale.

11Vulnérabilités
0Critiques
10Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de The Pack Elementor addon

11 fiches

CVE-2025-8214 Moyenne · 6,4
The Pack Elementor addon

The Pack Elementor addon <= 2.1.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Typing Letter Widget

The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typing Letter widget in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-2.1.5

Correctif

2.1.6

Publication

29/09/2025

CVE-2025-6550 Moyenne · 6,4
The Pack Elementor addon

The Pack Elementor addon <= 2.1.4 – Authenticated (Contributor+) Stored Cross-Site Scripting

The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_options’ parameter in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.1.4

Correctif

2.1.5

Publication

26/06/2025

CVE-2025-46472 Moyenne · 6,4
The Pack Elementor addon

The Pack Elementor addons <= 2.1.6 – Authenticated (Contributor+) Stored Cross-Site Scripting

The The Pack Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-2.1.6

Correctif

Non indiqué

Publication

24/04/2025

CVE-2025-30925 Moyenne · 6,4
The Pack Elementor addon

The Pack Elementor addons <= 2.1.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The The Pack Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-2.1.1

Correctif

2.1.2

Publication

27/03/2025

CVE-2024-52356 Moyenne · 6,4
The Pack Elementor addon

The Pack Elementor addons <= 2.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The The Pack Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-2.1.0

Correctif

2.1.1

Publication

08/11/2024

CVE-2024-47383 Moyenne · 6,4
The Pack Elementor addon

The Pack Elementor addons <= 2.0.8.8 – Authenticated (Author+) Stored Cross-Site Scripting

The The Pack Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level…

Versions affectées

*-2.0.8.8

Correctif

2.0.9

Publication

30/09/2024

CVE-2024-38768 Élevée · 8,8
The Pack Elementor addon

The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) <= 2.0.8.6 – Authenticated (contributor+) Local File Inclusion

The The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.8.6 via several blocks. This makes it possible for authenticated…

Versions affectées

*-2.0.8.6

Correctif

2.0.8.7

Publication

16/07/2024

CVE-2024-32785 Moyenne · 6,1
The Pack Elementor addon

The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) <= 2.0.8.3 – Reflected Cross-Site Scripting

The The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.0.8.3 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-2.0.8.3

Correctif

2.0.8.4

Publication

22/04/2024

CVE-2024-32718 Moyenne · 6,4
The Pack Elementor addon

The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) <= 2.0.8.2 – Authenticated (Subscriber+) Server-Side Request Forgery

The The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.8.2. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-2.0.8.2

Correctif

2.0.8.3

Publication

22/04/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités