Show filters
33 Total Results
Displaying 21-30 of 33
Sort by:
Attacker Value
Unknown
CVE-2024-2129
Disclosure Date: March 20, 2024 (last updated April 02, 2024)
The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's heading widget in all versions up to, and including, 1.3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2022-4950
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
0
Attacker Value
Unknown
CVE-2023-23683
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ozan Canakli White Label Branding for Elementor Page Builder plugin <= 1.0.2 versions.
0
Attacker Value
Unknown
CVE-2023-0484
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-47166
Disclosure Date: March 13, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions.
0
Attacker Value
Unknown
CVE-2021-24266
Disclosure Date: May 05, 2021 (last updated February 22, 2025)
The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
0
Attacker Value
Unknown
CVE-2020-20406
Disclosure Date: September 16, 2020 (last updated February 22, 2025)
A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.
0
Attacker Value
Unknown
CVE-2020-13865
Disclosure Date: June 05, 2020 (last updated February 21, 2025)
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.
0
Attacker Value
Unknown
CVE-2020-13864
Disclosure Date: June 05, 2020 (last updated February 21, 2025)
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.
0
Attacker Value
Unknown
CVE-2020-13126
Disclosure Date: May 17, 2020 (last updated February 21, 2025)
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
0