Show filters
55 Total Results
Displaying 31-40 of 55
Sort by:
Attacker Value
Unknown
CVE-2023-4975
Disclosure Date: October 20, 2023 (last updated October 27, 2023)
The Website Builder by SeedProd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.15.13.1. This is due to missing or incorrect nonce validation on functionality in the builder.php file. This makes it possible for unauthenticated attackers to change the stripe connect token via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2022-4953
Disclosure Date: August 14, 2023 (last updated October 08, 2023)
The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.
0
Attacker Value
Unknown
CVE-2020-36722
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
0
Attacker Value
Unknown
CVE-2020-36703
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts.
0
Attacker Value
Unknown
CVE-2023-0329
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.
0
Attacker Value
Unknown
CVE-2022-2516
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page 'Title' value in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2022-2430
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' feature in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2022-29455
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
0
Attacker Value
Unknown
CVE-2022-1329
Disclosure Date: April 19, 2022 (last updated February 23, 2025)
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.
0
Attacker Value
Unknown
CVE-2021-24891
Disclosure Date: November 23, 2021 (last updated February 23, 2025)
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.
0