CVE-2025-66066
- EPSS 0.04%
- Veröffentlicht 21.11.2025 12:29:55
- Zuletzt bearbeitet 20.01.2026 15:19:01
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo Extra envo-extra allows Stored XSS.This issue affects Envo Extra: from n/a through <= 1.9.11.
CVE-2025-47471
- EPSS 0.17%
- Veröffentlicht 07.05.2025 14:19:44
- Zuletzt bearbeitet 08.05.2025 14:39:18
Missing Authorization vulnerability in EnvoThemes Envo Extra allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Envo Extra: from n/a through 1.9.9.
CVE-2024-10770
- EPSS 0.24%
- Veröffentlicht 09.11.2024 05:15:08
- Zuletzt bearbeitet 29.01.2025 19:32:53
The Envo Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.3 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for a...
CVE-2024-5645
- EPSS 0.36%
- Veröffentlicht 07.06.2024 10:15:12
- Zuletzt bearbeitet 21.11.2024 09:48:05
The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_css_id’ parameter within the Button widget in all versions up to, and including, 1.8.23 due to insufficient input sanitization and output escaping. This ...
CVE-2024-4385
- EPSS 0.31%
- Veröffentlicht 16.05.2024 11:15:48
- Zuletzt bearbeitet 30.01.2025 16:09:33
The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 1.8.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...
CVE-2024-32456
- EPSS 0.18%
- Veröffentlicht 17.04.2024 10:15:10
- Zuletzt bearbeitet 05.02.2025 15:44:23
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo Extra allows Stored XSS.This issue affects Envo Extra: from n/a through 1.8.11.