Show filters
46 Total Results
Displaying 41-46 of 46
Sort by:
Attacker Value
Unknown
CVE-2021-24949
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise and escape the option parameter before using it in a SQL statement, which could lead to SQL injection
0
Attacker Value
Unknown
CVE-2021-24948
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthenticated users to retrieve sensitive information, such as private and draft posts
0
Attacker Value
Unknown
CVE-2021-24358
Disclosure Date: June 14, 2021 (last updated February 22, 2025)
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue.
0
Attacker Value
Unknown
CVE-2021-24351
Disclosure Date: June 14, 2021 (last updated February 22, 2025)
The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scripting (exploitable on both unauthenticated and authenticated users)
0
Attacker Value
Unknown
CVE-2021-24359
Disclosure Date: June 14, 2021 (last updated February 22, 2025)
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legitimate user, allowing an attacker to send an arbitrary reset password email to a registered user on behalf of the WordPress site. Such issue could be chained with an open redirect (CVE-2021-24358) in version below 4.1.10, to include a crafted password reset link in the email, which would lead to an account takeover.
0
Attacker Value
Unknown
CVE-2021-24266
Disclosure Date: May 05, 2021 (last updated February 22, 2025)
The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
0