Envothemes

Envo Extra

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 13.03.2026 11:42:09
  • Zuletzt bearbeitet 29.04.2026 10:17:03

Missing Authorization vulnerability in EnvoThemes Envo Extra envo-extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envo Extra: from n/a through <= 1.9.13.

  • EPSS 0.17%
  • Veröffentlicht 21.11.2025 12:29:55
  • Zuletzt bearbeitet 27.04.2026 18:16:32

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo Extra envo-extra allows Stored XSS.This issue affects Envo Extra: from n/a through <= 1.9.11.

  • EPSS 0.24%
  • Veröffentlicht 07.05.2025 14:19:44
  • Zuletzt bearbeitet 23.04.2026 15:30:16

Missing Authorization vulnerability in EnvoThemes Envo Extra envo-extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envo Extra: from n/a through <= 1.9.9.

  • EPSS 0.3%
  • Veröffentlicht 09.11.2024 05:15:08
  • Zuletzt bearbeitet 29.01.2025 19:32:53

The Envo Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.3 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for a...

  • EPSS 0.32%
  • Veröffentlicht 07.06.2024 10:15:12
  • Zuletzt bearbeitet 08.04.2026 19:21:58

The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_css_id’ parameter within the Button widget in all versions up to, and including, 1.8.23 due to insufficient input sanitization and output escaping. This ...

  • EPSS 0.34%
  • Veröffentlicht 16.05.2024 11:15:48
  • Zuletzt bearbeitet 08.04.2026 18:21:47

The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 1.8.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...

  • EPSS 0.32%
  • Veröffentlicht 17.04.2024 10:15:10
  • Zuletzt bearbeitet 28.04.2026 19:24:40

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo Extra allows Stored XSS.This issue affects Envo Extra: from n/a through 1.8.11.