Extension WordPress
Vulnérabilités UiCore Elements – Free widgets and templates for Elementor
Cette page rassemble les failles publiées pour UiCore Elements – Free widgets and templates for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de UiCore Elements – Free widgets and templates for Elementor
4 fiches
UiCore Elements <= 1.3.13 – Authenticated (Contributor+) Stored Cross-Site Scripting
The UiCore Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-1.3.13
1.3.14
01/03/2026
UiCore Elements <= 1.3.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The UiCore Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-1.3.4
1.3.5
27/08/2025
UiCore Elements <= 1.3.0 – Missing Authorization to Unauthenticated Arbitrary File Read
The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.3.0 via the prepare_template() function due to a missing capability check and insufficient…
*-1.3.0
1.3.1
11/08/2025
UiCore Elements – Free Elementor widgets and templates <= 1.0.16 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the UI Counter, UI Icon Box, UI Testimonial Slider, UI Testimonial Grid, and UI Testimonial Carousel widgets in all…
*-1.0.16
1.2.0
22/04/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.