Show filters
214 Total Results
Displaying 121-130 of 214
Sort by:
Attacker Value
Unknown
CVE-2022-47175
Disclosure Date: October 06, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in P Royal Royal Elementor Addons and Templates plugin <= 1.3.75 versions.
0
Attacker Value
Unknown
CVE-2022-4953
Disclosure Date: August 14, 2023 (last updated October 08, 2023)
The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.
0
Attacker Value
Unknown
CVE-2023-39144
Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.
0
Attacker Value
Unknown
CVE-2023-3709
Disclosure Date: July 18, 2023 (last updated November 09, 2023)
The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp API key. We recommend resetting any MailChimp API keys if running a vulnerable version of this plugin with the MailChimp block enabled as the API key may have been compromised.
0
Attacker Value
Unknown
CVE-2023-3295
Disclosure Date: June 17, 2023 (last updated February 25, 2025)
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authenticated attackers, with contributor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The issue was partially patched in version 1.5.66 and fully patched in 1.5.67. CVE-2023-31231 appears to be a duplicate of this issue.
0
Attacker Value
Unknown
CVE-2023-1169
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'file_uploader_callback' function in versions up to, and including, 2.1.4. This makes it possible for subscriber-level attackers to upload image attachments to the site.
0
Attacker Value
Unknown
CVE-2023-3124
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.
0
Attacker Value
Unknown
CVE-2020-36703
Disclosure Date: June 07, 2023 (last updated February 25, 2025)
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts.
0
Attacker Value
Unknown
CVE-2023-0329
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.
0
Attacker Value
Unknown
CVE-2022-47139
Disclosure Date: May 25, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Damir Calusic WP Basic Elements plugin <= 5.2.15 versions.
0