Extension WordPress

Vulnérabilités The Plus Addons for Elementor Page Builder Pro

Cette page rassemble les failles publiées pour The Plus Addons for Elementor Page Builder Pro, leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
3Critiques
13Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de The Plus Addons for Elementor Page Builder Pro

13 fiches

CVE-2024-5344 Moyenne · 6,1
The Plus Addons for Elementor Page Builder Pro

The Plus Addons for Elementor Page Builder <= 5.5.6 – Reflected Cross-Site Scripting via WP Login and Register Widget

The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘forgoturl’ attribute within the plugin's WP Login & Register widget in all versions up to, and including, 5.5.6 due…

Versions affectées

*-5.5.6

Correctif

5.6.0

Publication

20/06/2024

CVE-2024-5455 Élevée · 8,8
The Plus Addons for Elementor Page Builder Pro

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.6 – Authenticated (Contributor+) Local File Inclusion

The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.5.4 via the 'magazine_style' parameter within the Dynamic Smart Showcase widget. This makes it possible…

Versions affectées

*-5.5.6

Correctif

5.6.0

Publication

20/06/2024

CVE-2024-5341 Moyenne · 6,4
The Plus Addons for Elementor Page Builder Pro

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Heading Title Widget

The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' attribute of the Heading Title widget in all versions up to, and including, 5.5.4 due to insufficient input…

Versions affectées

*-5.5.4

Correctif

5.5.5

Publication

29/05/2024

CVE-2021-24948 Élevée · 7,5
The Plus Addons for Elementor Page Builder Pro

The Plus Addons for Elementor Pro <= 5.0.6 – Sensitive Data Disclosure

The Plus Addons for Elementor – Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthenticated users to retrieve sensitive information, such as private and draft posts

Versions affectées

[*, 5.0.7)

Correctif

5.0.7

Publication

13/12/2021

CVE-2021-24351 Moyenne · 6,1
The Plus Addons for Elementor Page Builder Pro

The Plus Addons for Elementor Page Builder <= 4.1.11 – Reflected Cross-Site Scripting

The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scripting (exploitable on both unauthenticated and authenticated users)

Versions affectées

[*, 4.1.12)

Correctif

4.1.12

Publication

31/05/2021

CVE-2021-4331 Élevée · 8,8
The Plus Addons for Elementor Page Builder Pro

The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 – Authenticated (Contributor+) Privilege Escalation

The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registration form to the Elementor page builders functionality. As part…

Versions affectées

*-4.1.9

Correctif

4.1.10

Publication

14/04/2021

CVE-2021-24175 Critique · 9,8
The Plus Addons for Elementor Page Builder Pro

Plus Addons for Elementor Page Builder <= 4.1.6 – Authentication Bypass

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related…

Versions affectées

[*, 4.1.7)

Correctif

4.1.7

Publication

08/03/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités