Extension WordPress
Vulnérabilités Themesflat Addons For Elementor
Cette page rassemble les failles publiées pour Themesflat Addons For Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Themesflat Addons For Elementor
13 fiches
themesflat-addons-for-elementor <= 2.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The themesflat-addons-for-elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-2.3.2
2.3.3
23/03/2026
Themesflat Addons For Elementor <= 2.2.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider widget in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes…
*-2.2.5
2.2.6
18/04/2025
Themesflat Addons For Elementor <= 2.3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-2.3.1
2.3.2
31/03/2025
Themesflat Addons For Elementor <= 2.2.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes…
*-2.2.4
2.2.5
07/01/2025
Themesflat Addons For Elementor <= 2.2.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-2.2.2
2.2.3
02/12/2024
Themesflat Addons For Elementor <= 2.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-2.2.1
2.2.2
15/10/2024
Themesflat Addons For Elementor <= 2.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in all versions up to, and including, 2.2.1…
*-2.2.1
2.2.2
24/09/2024
Themesflat Addons For Elementor <= 2.2.1 – Authenticated (Contributor+) Information Exposure
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
*-2.2.1
2.2.2
24/09/2024
Themesflat Addons For Elementor <= 2.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Tags
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget tags in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-2.1.2
2.1.3
05/06/2024
Themesflat Addons For Elementor <= 2.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via URLs
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets via URL parameters in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes…
*-2.1.2
2.1.3
05/06/2024
Themesflat Addons For Elementor <= 2.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting in Multiple Widgets
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TF Group Image, TF Nav Menu, TF Posts, TF Woo Product Grid, TF Accordion, and TF Image Box widgets in all…
*-2.1.2
2.1.3
05/06/2024
Themesflat Addons For Elementor <= 2.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Titles
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget's titles in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied…
*-2.1.2
2.1.3
05/06/2024
Themesflat Addons For Elementor <= 2.0.0 – Unauthenticated PHP Object Injection
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.0 via deserialization of untrusted input through the 'settings' parameter retrieved from the tf_product_filter nopriv AJAX action. This…
*-2.0.0
2.0.1
07/08/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.