Extension WordPress
Vulnérabilités Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor
Cette page rassemble les failles publiées pour Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor
6 fiches
Thim Kit for Elementor <= 1.3.7 – Missing Authorization to Unauthenticated Private Course Disclosure
The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing validation checks on the 'thim-ekit/archive-course/get-courses' REST endpoint callback function in all versions…
*-1.3.7
1.3.8
14/03/2026
Thim Elementor Kit <= 1.3.3 – Authenticated (Contributor+) Insecure Direct Object Reference
The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.3 due to missing validation on a user controlled…
*-1.3.3
1.3.4
06/12/2025
Thim Elementor Kit <= 1.2.8 – Missing Authorization
The Thim Elementor Kit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with Contributor-level…
*-1.2.8
1.2.9
24/01/2025
Thim Elementor Kit <= 1.2.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.2.9
1.2.9.1
06/01/2025
Thim Elementor Kit <= 1.1.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.1.9
1.1.9.1
10/05/2024
Thim Elementor Kit <= 1.1.8 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.1.8
1.1.9
06/05/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.