CVE-2024-2399
- EPSS 0.1%
- Veröffentlicht 15.03.2024 07:15:09
- Zuletzt bearbeitet 23.01.2025 19:27:52
The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 4.10.23 due to insufficient input sanitization and output escaping on user supplied attributes. Th...
CVE-2024-1680
- EPSS 0.23%
- Veröffentlicht 13.03.2024 16:15:25
- Zuletzt bearbeitet 15.01.2025 18:42:45
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Settings URL of the Banner, Team Members, and Image Scroll widgets in all versions up to, and including, 4.10.21 due to insufficient inpu...
CVE-2024-0326
- EPSS 0.27%
- Veröffentlicht 13.03.2024 16:15:10
- Zuletzt bearbeitet 08.01.2025 18:33:51
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Link Wrapper functionality in all versions up to, and including, 4.10.17 due to insufficient input sanitization and output escaping on...
CVE-2024-1242
- EPSS 0.32%
- Veröffentlicht 29.02.2024 01:43:44
- Zuletzt bearbeitet 15.08.2025 20:33:58
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 4.10.18 due to insufficient input sanitization and output escaping. This makes i...
CVE-2024-24831
- EPSS 0.08%
- Veröffentlicht 10.02.2024 08:15:09
- Zuletzt bearbeitet 21.11.2024 08:59:48
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Addons for Elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.10.16.
CVE-2023-34012
- EPSS 0.08%
- Veröffentlicht 23.06.2023 12:15:09
- Zuletzt bearbeitet 21.11.2024 08:06:24
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premium Addons for Elementor Premium Addons PRO plugin <= 2.8.24 versions.
CVE-2021-24257
- EPSS 0.22%
- Veröffentlicht 05.05.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 05:52:42
The “Premium Addons for Elementor” WordPress Plugin before 4.2.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.