Crocoblock

Jetwidgets For Elementor

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 12.11.2024 07:15:03
  • Zuletzt bearbeitet 05.02.2025 17:18:49

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.0.18 due to insufficient input sanitization and output escaping. This makes it possib...

  • EPSS 1.63%
  • Veröffentlicht 01.08.2024 21:15:28
  • Zuletzt bearbeitet 02.08.2024 12:59:43

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetWidgets for Elementor and WooCommerce allows PHP Local File Inclusion.This issue affects JetWidgets for Elementor and WooCommerce: from n/a ...

  • EPSS 0.36%
  • Veröffentlicht 20.06.2024 02:15:11
  • Zuletzt bearbeitet 21.11.2024 09:43:14

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_type’ and 'id' parameters in all versions up to, and including, 1.0.17 due to insufficient input sanitization and output escaping. This mak...

  • EPSS 0.2%
  • Veröffentlicht 09.04.2024 19:15:34
  • Zuletzt bearbeitet 05.02.2025 17:28:13

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL in all versions up to, and including, 1.0.16 due to insufficient input sanitization and output escaping on user supplied attribut...

  • EPSS 0.23%
  • Veröffentlicht 09.04.2024 19:15:28
  • Zuletzt bearbeitet 31.01.2025 01:41:07

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animated Box widget in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 13.02.2023 15:15:20
  • Zuletzt bearbeitet 14.01.2025 22:15:25

The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and a...

  • EPSS 0.08%
  • Veröffentlicht 05.01.2023 17:15:09
  • Zuletzt bearbeitet 21.11.2024 07:36:31

The JetWidgets for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.12. This is due to missing nonce validation on the save() function. This makes it possible for unauthenticated attacke...

  • EPSS 0.22%
  • Veröffentlicht 05.05.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:52:43

The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.