CVE-2024-53786
- EPSS 0.06%
- Veröffentlicht 30.11.2024 22:15:19
- Zuletzt bearbeitet 05.02.2025 14:46:20
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons allows Stored XSS.This issue affects Cowidgets – Elementor Addons: from n/a through 1.2.0.
CVE-2024-10779
- EPSS 0.27%
- Veröffentlicht 09.11.2024 03:15:05
- Zuletzt bearbeitet 29.01.2025 20:07:24
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.0 via the 'ce_template' shortcode due to insufficient restrictions on which posts can be included. This makes it pos...
CVE-2024-8960
- EPSS 0.25%
- Veröffentlicht 09.11.2024 03:15:05
- Zuletzt bearbeitet 29.01.2025 19:36:35
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for...
CVE-2024-5179
- EPSS 0.33%
- Veröffentlicht 06.06.2024 02:15:54
- Zuletzt bearbeitet 21.11.2024 09:47:08
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 via the 'item_style' and 'style' parameters. This makes it possible for authenticated attackers, with Contributor-...
CVE-2024-4697
- EPSS 0.47%
- Veröffentlicht 04.06.2024 06:15:11
- Zuletzt bearbeitet 30.01.2025 19:43:10
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_tag’ parameter in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it p...