CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Crocoblock 1Jetwidgets For Elementor Feb 5, 2025 Nov 12, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.0.18 due to insufficient input sanitization and output...Show more |
1Crocoblock 1Jetwidgets For Elementor Apr 8, 2026 Jun 20, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_type’ and 'id' parameters in all versions up to, and including, 1.0.17 due to insufficient input sanitization...Show more |
The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL in all versions up to, and including, 1.0.16 due to insufficient input sanitization and output esca...Show more |
The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animated Box widget in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output es...Show more |
1Crocoblock 1Jetwidgets For Elementor Jun 17, 2026 Feb 13, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users w...Show more |
1Crocoblock 1Jetwidgets For Elementor Jun 17, 2026 Jan 5, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The JetWidgets for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.12. This is due to missing nonce validation on the save() function. This makes it possib...Show more |
1Crocoblock 1Jetwidgets For Elementor Jun 17, 2026 May 5, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. |