CVE-2023-5381
- EPSS 0.12%
- Veröffentlicht 15.11.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 08:41:39
The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.12.7 due to insufficient input sanitization and output escaping. This makes it possible for authenti...
CVE-2023-4723
- EPSS 0.23%
- Veröffentlicht 15.11.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:49
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.12.7 via the ajax_eae_post_data function. This can allow unauthenticated attackers to extract sensitive data includi...
CVE-2023-4690
- EPSS 0.05%
- Veröffentlicht 15.11.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:41
The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.12.7. This is due to missing or incorrect nonce validation on the eae_save_config function. This makes it possible for u...
CVE-2023-4689
- EPSS 0.05%
- Veröffentlicht 15.11.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:41
The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.12.7. This is due to missing or incorrect nonce validation on the eae_save_elements function. This makes it possible for...
CVE-2021-24259
- EPSS 0.22%
- Veröffentlicht 05.05.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:52:42
The “Elementor Addon Elements” WordPress Plugin before 1.11.2 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.