CVE-2024-54212
- EPSS 0.06%
- Published 06.12.2024 14:15:26
- Last modified 03.02.2025 14:33:05
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.2.6.
CVE-2024-10352
- EPSS 0.14%
- Published 09.11.2024 12:15:17
- Last modified 29.01.2025 19:10:38
The Magical Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the get_content_type function in includes/widgets/content-reveal.php. This makes it possible for aut...
CVE-2024-51665
- EPSS 25.54%
- Published 04.11.2024 14:15:16
- Last modified 06.11.2024 22:07:10
Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through 1.2.1.
CVE-2024-38730
- EPSS 0.1%
- Published 22.07.2024 11:15:04
- Last modified 21.11.2024 09:26:42
Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor.This issue affects Magical Addons For Elementor: from n/a through 1.1.41.
CVE-2024-38681
- EPSS 0.06%
- Published 20.07.2024 08:15:07
- Last modified 03.02.2025 16:03:37
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.1.41.
CVE-2024-5161
- EPSS 0.17%
- Published 06.06.2024 04:15:14
- Last modified 21.11.2024 09:47:06
The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 1.1.39 due...
CVE-2024-2923
- EPSS 0.31%
- Published 14.05.2024 15:21:26
- Last modified 28.01.2025 03:20:18
The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including...
CVE-2024-34547
- EPSS 0.29%
- Published 08.05.2024 12:15:08
- Last modified 28.01.2025 03:28:09
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.1.34.