Show filters
214 Total Results
Displaying 121-130 of 214
Sort by:
Attacker Value
Unknown

CVE-2022-47175

Disclosure Date: October 06, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in P Royal Royal Elementor Addons and Templates plugin <= 1.3.75 versions.
Attacker Value
Unknown

CVE-2022-4953

Disclosure Date: August 14, 2023 (last updated October 08, 2023)
The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.
Attacker Value
Unknown

CVE-2023-39144

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.
Attacker Value
Unknown

CVE-2023-3709

Disclosure Date: July 18, 2023 (last updated November 09, 2023)
The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp API key. We recommend resetting any MailChimp API keys if running a vulnerable version of this plugin with the MailChimp block enabled as the API key may have been compromised.
Attacker Value
Unknown

CVE-2023-3295

Disclosure Date: June 17, 2023 (last updated February 25, 2025)
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authenticated attackers, with contributor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The issue was partially patched in version 1.5.66 and fully patched in 1.5.67. CVE-2023-31231 appears to be a duplicate of this issue.
Attacker Value
Unknown

CVE-2023-1169

Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'file_uploader_callback' function in versions up to, and including, 2.1.4. This makes it possible for subscriber-level attackers to upload image attachments to the site.
Attacker Value
Unknown

CVE-2023-3124

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.
Attacker Value
Unknown

CVE-2020-36703

Disclosure Date: June 07, 2023 (last updated February 25, 2025)
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts.
Attacker Value
Unknown

CVE-2023-0329

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.
Attacker Value
Unknown

CVE-2022-47139

Disclosure Date: May 25, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Damir Calusic WP Basic Elements plugin <= 5.2.15 versions.