Extension WordPress

Vulnérabilités Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

Cette page rassemble les failles publiées pour Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
4Critiques
12Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

12 fiches

CVE-2025-58017 Moyenne · 6,4
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

Ultimate Store Kit Elementor Addons <= 2.8.6 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Ultimate Store Kit Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-2.8.6

Correctif

2.8.7

Publication

22/09/2025

CVE-2025-2168 Moyenne · 4,3
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.4.1 – Cross-Site Request Forgery to Limited User Meta Update

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.1. This is…

Versions affectées

*-2.4.1

Correctif

2.5.0

Publication

30/04/2025

CVE-2025-39588 Critique · 9,8
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

Ultimate Store Kit Elementor Addons <= 2.4.0 – Unauthenticated PHP Object Injection

The Ultimate Store Kit – Elementor powered WooCommerce Builder, 80+ Widgets and Template Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.0 via deserialization of untrusted input. This makes…

Versions affectées

*-2.4.0

Correctif

2.4.1

Publication

17/04/2025

CVE-2025-32184 Moyenne · 6,4
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

Ultimate Store Kit Elementor Addons <= 2.5.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Ultimate Store Kit Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-2.5.0

Correctif

2.6.0

Publication

04/04/2025

CVE-2025-24584 Moyenne · 4,3
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.3.0 – Missing Authorization

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all…

Versions affectées

*-2.3.0

Correctif

2.3.1

Publication

19/12/2024

CVE-2024-47629 Moyenne · 6,4
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

Ultimate Store Kit Elementor Addons <= 2.0.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Ultimate Store Kit Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-2.0.5

Correctif

2.0.6

Publication

30/09/2024

CVE-2024-8030 Critique · 9,8
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.0.3 – Unauthenticated PHP Object Injection

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_wishlist cookie in versions up…

Versions affectées

*-2.0.3

Correctif

2.0.4

Publication

27/08/2024

CVE-2024-5335 Critique · 9,8
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 1.6.4 – Unauthenticated PHP Object Injection

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_compare_products cookie in versions up…

Versions affectées

*-1.6.4

Correctif

2.0.0

Publication

20/08/2024

CVE-2024-43342 Moyenne · 6,4
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

Ultimate Store Kit Elementor Addons <= 1.6.4 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Ultimate Store Kit Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.6.4

Correctif

2.0.0

Publication

16/08/2024

CVE-2024-4606 Critique · 9,8
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

Ultimate Store Kit Elementor Addons <= 2.0.3 – Unauthenticated PHP Object Injection

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.3 via deserialization…

Versions affectées

*-2.0.3

Correctif

2.0.4

Publication

07/05/2024

CVE-2024-31357 Moyenne · 6,4
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor

Ultimate Store Kit Elementor Addons <= 1.5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Ultimate Store Kit Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.5.2

Correctif

1.6.0

Publication

08/04/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités