Show filters
114 Total Results
Displaying 71-80 of 114
Sort by:
Attacker Value
Unknown
CVE-2023-3709
Disclosure Date: July 18, 2023 (last updated November 09, 2023)
The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp API key. We recommend resetting any MailChimp API keys if running a vulnerable version of this plugin with the MailChimp block enabled as the API key may have been compromised.
0
Attacker Value
Unknown
CVE-2023-1169
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'file_uploader_callback' function in versions up to, and including, 2.1.4. This makes it possible for subscriber-level attackers to upload image attachments to the site.
0
Attacker Value
Unknown
CVE-2023-3124
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.
0
Attacker Value
Unknown
CVE-2020-36703
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts.
0
Attacker Value
Unknown
CVE-2023-0329
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.
0
Attacker Value
Unknown
CVE-2023-23683
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ozan Canakli White Label Branding for Elementor Page Builder plugin <= 1.0.2 versions.
0
Attacker Value
Unknown
CVE-2023-0336
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.
0
Attacker Value
Unknown
CVE-2022-4711
Disclosure Date: January 10, 2023 (last updated February 24, 2025)
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_settings' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to enable and modify Mega Menu settings for any menu item.
0
Attacker Value
Unknown
CVE-2022-4710
Disclosure Date: January 10, 2023 (last updated October 08, 2023)
The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.59, due to due to insufficient input sanitization and output escaping of the 'wpr_ajax_search_link_target' parameter in the 'data_fetch' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is occurring because 'sanitize_text_field' is insufficient to prevent attribute-based Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2022-4709
Disclosure Date: January 10, 2023 (last updated February 24, 2025)
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import and activate templates from the plugin's template library.
0