CVE-2024-54314
- EPSS 0.13%
- Veröffentlicht 13.12.2024 15:15:37
- Zuletzt bearbeitet 11.04.2025 14:57:42
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NicheAddons Primary Addon for Elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through 1.6.0.
CVE-2024-10670
- EPSS 0.08%
- Veröffentlicht 28.11.2024 10:15:04
- Zuletzt bearbeitet 11.04.2025 14:56:12
The Primary Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.2 via the [prim_elementor_template] shortcode due to insufficient restrictions on which posts can be included. This m...
CVE-2024-49259
- EPSS 0.16%
- Veröffentlicht 17.10.2024 20:15:06
- Zuletzt bearbeitet 24.03.2025 15:10:36
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NicheAddons Primary Addon for Elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through 1.5.8.
CVE-2024-44033
- EPSS 0.2%
- Veröffentlicht 06.10.2024 13:15:13
- Zuletzt bearbeitet 24.03.2025 15:09:08
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NicheAddons Primary Addon for Elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through 1.5.7.
CVE-2024-5229
- EPSS 0.27%
- Veröffentlicht 25.05.2024 03:15:08
- Zuletzt bearbeitet 21.11.2024 09:47:13
The Primary Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping on user sup...