Extension WordPress

Vulnérabilités Themesflat Addons For Elementor

Cette page rassemble les failles publiées pour Themesflat Addons For Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
1Critiques
13Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Themesflat Addons For Elementor

13 fiches

CVE-2026-39500 Moyenne · 6,4
Themesflat Addons For Elementor

themesflat-addons-for-elementor <= 2.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The themesflat-addons-for-elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-2.3.2

Correctif

2.3.3

Publication

23/03/2026

CVE-2025-3275 Moyenne · 6,4
Themesflat Addons For Elementor

Themesflat Addons For Elementor <= 2.2.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider widget in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.2.5

Correctif

2.2.6

Publication

18/04/2025

CVE-2025-31567 Moyenne · 6,4
Themesflat Addons For Elementor

Themesflat Addons For Elementor <= 2.3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-2.3.1

Correctif

2.3.2

Publication

31/03/2025

CVE-2024-12205 Moyenne · 6,4
Themesflat Addons For Elementor

Themesflat Addons For Elementor <= 2.2.4 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.2.4

Correctif

2.2.5

Publication

07/01/2025

CVE-2024-53796 Moyenne · 6,4
Themesflat Addons For Elementor

Themesflat Addons For Elementor <= 2.2.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-2.2.2

Correctif

2.2.3

Publication

02/12/2024

CVE-2024-49310 Moyenne · 6,4
Themesflat Addons For Elementor

Themesflat Addons For Elementor <= 2.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-2.2.1

Correctif

2.2.2

Publication

15/10/2024

CVE-2024-8516 Moyenne · 4,3
Themesflat Addons For Elementor

Themesflat Addons For Elementor <= 2.2.1 – Authenticated (Contributor+) Information Exposure

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to…

Versions affectées

*-2.2.1

Correctif

2.2.2

Publication

24/09/2024

CVE-2024-2922 Moyenne · 6,4
Themesflat Addons For Elementor

Themesflat Addons For Elementor <= 2.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Tags

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget tags in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This…

Versions affectées

*-2.1.2

Correctif

2.1.3

Publication

05/06/2024

CVE-2024-4458 Moyenne · 6,4
Themesflat Addons For Elementor

Themesflat Addons For Elementor <= 2.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via URLs

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets via URL parameters in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.1.2

Correctif

2.1.3

Publication

05/06/2024

CVE-2024-4212 Moyenne · 6,4
Themesflat Addons For Elementor

Themesflat Addons For Elementor <= 2.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting in Multiple Widgets

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TF Group Image, TF Nav Menu, TF Posts, TF Woo Product Grid, TF Accordion, and TF Image Box widgets in all…

Versions affectées

*-2.1.2

Correctif

2.1.3

Publication

05/06/2024

CVE-2024-4459 Moyenne · 6,4
Themesflat Addons For Elementor

Themesflat Addons For Elementor <= 2.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Titles

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget's titles in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied…

Versions affectées

*-2.1.2

Correctif

2.1.3

Publication

05/06/2024

CVE-2023-37390 Critique · 9,8
Themesflat Addons For Elementor

Themesflat Addons For Elementor <= 2.0.0 – Unauthenticated PHP Object Injection

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.0 via deserialization of untrusted input through the 'settings' parameter retrieved from the tf_product_filter nopriv AJAX action. This…

Versions affectées

*-2.0.0

Correctif

2.0.1

Publication

07/08/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités