CVE-2026-103063
- EPSS 0.13%
- Veröffentlicht 01.10.2026 12:33:43
- Zuletzt bearbeitet 01.10.2026 14:34:35
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4....
CVE-2026-103064
- EPSS 0.13%
- Veröffentlicht 01.10.2026 12:32:30
- Zuletzt bearbeitet 01.10.2026 14:34:35
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4....
CVE-2026-49052
- EPSS 0.15%
- Veröffentlicht 27.05.2026 15:16:33
- Zuletzt bearbeitet 27.05.2026 19:43:00
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.
CVE-2026-49053
- EPSS 0.19%
- Veröffentlicht 27.05.2026 15:16:33
- Zuletzt bearbeitet 27.05.2026 19:43:00
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.
CVE-2025-0321
- EPSS 0.26%
- Veröffentlicht 28.01.2025 08:15:29
- Zuletzt bearbeitet 30.01.2025 17:39:45
The ElementsKit Pro plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for...
CVE-2024-43996
- EPSS 0.62%
- Veröffentlicht 23.09.2024 01:15:11
- Zuletzt bearbeitet 08.01.2025 16:16:57
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit Pro allows PHP Local File Inclusion.This issue affects ElementsKit Pro: from n/a through 3.6.0.
CVE-2024-7064
- EPSS 0.26%
- Veröffentlicht 15.08.2024 06:15:12
- Zuletzt bearbeitet 08.01.2025 20:30:58
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authentica...
CVE-2024-7063
- EPSS 0.35%
- Veröffentlicht 15.08.2024 06:15:11
- Zuletzt bearbeitet 08.01.2025 20:33:37
The ElementsKit Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.6 via the 'render_raw' function. This can allow authenticated attackers, with Contributor-level permissions and above, ...
CVE-2024-5263
- EPSS 0.26%
- Veröffentlicht 15.06.2024 02:15:51
- Zuletzt bearbeitet 08.04.2026 17:19:01
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and Table widgets in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user suppli...
CVE-2024-4404
- EPSS 0.32%
- Veröffentlicht 14.06.2024 06:15:12
- Zuletzt bearbeitet 08.04.2026 18:21:48
The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' function. This can allow authenticated attackers, with contributor-level permissions and above, to make...