CVE-2025-3614
- EPSS 0.04%
- Published 24.07.2025 23:15:26
- Last modified 28.07.2025 15:07:38
The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom widget in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output es...
CVE-2025-4479
- EPSS 0.04%
- Published 19.06.2025 03:40:13
- Last modified 10.07.2025 00:06:38
The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin image comparison widget's before/after labels in all versions up to, and including, 3.5.2 due to insufficient input saniti...
CVE-2024-11180
- EPSS 0.02%
- Published 29.03.2025 07:23:45
- Last modified 29.07.2025 23:20:53
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to insufficient input sanitization ...
CVE-2025-0968
- EPSS 0.11%
- Published 19.02.2025 12:15:31
- Last modified 25.02.2025 20:21:17
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function. This makes it possible for u...
CVE-2025-1005
- EPSS 0.05%
- Published 15.02.2025 10:15:08
- Last modified 24.02.2025 12:31:01
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping on user ...
CVE-2024-8546
- EPSS 0.04%
- Published 25.09.2024 13:15:04
- Last modified 02.10.2024 18:56:40
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user supplied a...
CVE-2023-6525
- EPSS 0.15%
- Published 16.03.2024 03:15:06
- Last modified 08.01.2025 18:14:29
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar element attributes in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This ma...