CVE-2024-3733
- EPSS 0.39%
- Veröffentlicht 25.04.2024 09:15:08
- Zuletzt bearbeitet 10.01.2025 21:36:36
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_...
CVE-2024-3645
- EPSS 0.17%
- Veröffentlicht 22.04.2024 14:15:07
- Zuletzt bearbeitet 10.01.2025 21:33:19
The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Counter widget in all versions up to, and including, 5.8.11 due to insufficient input sanitization and output escaping on user s...
CVE-2024-3333
- EPSS 0.24%
- Veröffentlicht 17.04.2024 12:15:07
- Zuletzt bearbeitet 08.01.2025 19:43:24
The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attributes of widgets in all versions up to, and including, 5.9.14 due to insufficient input sanitization and output escaping on user sup...
CVE-2024-2974
- EPSS 0.39%
- Veröffentlicht 09.04.2024 19:15:38
- Zuletzt bearbeitet 08.01.2025 20:06:14
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can all...
CVE-2024-2650
- EPSS 0.18%
- Veröffentlicht 09.04.2024 19:15:35
- Zuletzt bearbeitet 08.01.2025 20:06:29
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the alignment parameter in the Woo Product Carousel widget in all versions up to...
CVE-2024-2623
- EPSS 0.21%
- Veröffentlicht 09.04.2024 19:15:35
- Zuletzt bearbeitet 08.01.2025 20:15:47
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's message parameter in all versions up to, and including, 5...
CVE-2024-3018
- EPSS 1.09%
- Veröffentlicht 30.03.2024 12:15:07
- Zuletzt bearbeitet 08.01.2025 19:35:58
The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the "Login | Register Form" ...
CVE-2024-1537
- EPSS 0.13%
- Veröffentlicht 13.03.2024 16:15:24
- Zuletzt bearbeitet 08.01.2025 19:09:15
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Data Table widget in all versions up to, and including, 5.9.9 due t...
CVE-2024-1536
- EPSS 0.21%
- Veröffentlicht 13.03.2024 16:15:24
- Zuletzt bearbeitet 08.01.2025 18:32:08
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's event calendar widget in all versions up to, and including, 5.9.9 d...
CVE-2024-1276
- EPSS 0.21%
- Veröffentlicht 29.02.2024 01:43:46
- Zuletzt bearbeitet 08.01.2025 18:37:36
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Content Ticker arrow attribute in all versions up to, and including, 5.9.8 d...