Extension WordPress
Vulnérabilités All-in-One Addons for Elementor – WidgetKit
Cette page rassemble les failles publiées pour All-in-One Addons for Elementor – WidgetKit, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de All-in-One Addons for Elementor – WidgetKit
10 fiches
All-in-One Addons for Elementor – WidgetKit <= 2.5.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Team and Countdown Widgets
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Team and Countdown widgets in all versions up to, and including, 2.5.6 due to insufficient input sanitization and output…
*-2.5.6
2.5.7
12/12/2025
All-in-One Addons for Elementor – WidgetKit <= 2.5.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via button+modal Widget
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button+modal' widget in all versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping on…
*-2.5.4
2.5.5
01/07/2025
WidgetKit <= 2.5.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-2.5.4
2.5.5
30/05/2025
All-in-One Addons for Elementor – WidgetKit <= 2.5.5 – Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.5 in elements/advanced-tab/template/view.php. This makes it possible for authenticated attackers, with Contributor-level access and above,…
*-2.5.5
Non indiqué
07/03/2025
WidgetKit <= 2.5.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-2.5.0
2.5.1
28/06/2024
All-in-One Addons for Elementor – WidgetKit <= 2.4.8 – Authenticated (Contributor+) Stored Cross-Site Scripting
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-2.4.8
2.5.0
07/05/2024
WidgetKit <= 2.5.4 – Missing Authorization to Notice Dismissal
The WidgetKit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wk_td_ads_dismiss_notice() function in versions up to, and including, 2.5.4. This makes it possible for unauthenticated attackers to dismiss…
*-2.5.4
2.5.5
29/04/2024
All-in-One Addons for Elementor – WidgetKit <= 2.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Widgets
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple pricing widgets (e.g. Pricing Single, Pricing Icon, Pricing Tab) in all versions up to, and including, 2.5.1 due to insufficient…
*-2.5.1
Non indiqué
11/04/2024
All-in-One Addons for Elementor – WidgetKit <= 2.4.3 – Authenticated (Administrator+) Stored Cross-Site Scripting
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping. This makes it…
*-2.4.3
2.4.4
06/12/2022
All-in-One Addons for Elementor – WidgetKit <= 2.3.9 – Contributor+ Stored Cross-Site Scripting
The “All-in-One Addons for Elementor – WidgetKit” WordPress Plugin before 2.3.10 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
[*, 2.3.10)
2.3.10
13/04/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.