CVEs (36)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the subcontainer value parameter in all versions up to, and including, 4.10.28 due to insufficient input sanitization...Show more |
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's post ticker widget in all versions up to, and including, 4.10.28 due to insufficient input sanitization...Show more |
1Leap13 1Premium Addons For Elementor Apr 23, 2026 Apr 24, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor.This issue affects Premium Addons for Elementor: from...Show more |
1Leap13 1Premium Addons For Elementor Apr 28, 2026 Apr 10, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Insertion of Sensitive Information Into Sent Data vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor.This issue affects Premium Addons for Elementor: from n/a through <= 4.10.22. |
1Leap13 1Premium Addons For Elementor Apr 8, 2026 Apr 10, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Bullet List Widget in all versions up to, and including, 4.10.24 due to insufficient input san...Show more |
1Leap13 1Premium Addons For Elementor Apr 8, 2026 Apr 10, 2024 N/A· v4 6.4 MEDIUM· v3 N/A· v2 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button in all versions up to, and including, 4.10.27 due to insufficient input sanitization and output e...Show more |
1Leap13 1Premium Addons For Elementor Apr 8, 2026 Apr 10, 2024 N/A· v4 6.4 MEDIUM· v3 N/A· v2 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown Widget in all versions up to, and including, 4.10.24 due to insufficient input sanitization an...Show more |
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Wrapper Link Widget in all versions up to, and including, 4.10.16 due to insufficient input sanitization...Show more |
1Leap13 1Premium Addons For Elementor Apr 28, 2026 Mar 19, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Addons for Elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a throug...Show more |
1Leap13 1Premium Addons For Elementor Apr 8, 2026 Mar 15, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 4.10.23 due to insufficient input sanitization and output...Show more |
1Leap13 1Premium Addons For Elementor Apr 8, 2026 Mar 13, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Settings URL of the Banner, Team Members, and Image Scroll widgets in all versions up to, and including, 4....Show more |
1Leap13 1Premium Addons For Elementor Apr 8, 2026 Mar 13, 2024 N/A· v4 6.4 MEDIUM· v3 N/A· v2 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Link Wrapper functionality in all versions up to, and including, 4.10.17 due to insufficient input sanit...Show more |
1Leap13 1Premium Addons For Elementor Apr 8, 2026 Feb 29, 2024 N/A· v4 6.4 MEDIUM· v3 N/A· v2 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 4.10.18 due to insufficient input sanitization and...Show more |
1Leap13 1Premium Addons For Elementor Apr 23, 2026 Feb 10, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor.This issue affects Premium Addons for Elementor: from...Show more |
1Leap13 1Premium Addons For Elementor Nov 21, 2024 Jun 23, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premium Addons for Elementor Premium Addons PRO plugin <= 2.8.24 versions. |
1Leap13 1Premium Addons For Elementor Nov 21, 2024 May 5, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The “Premium Addons for Elementor” WordPress Plugin before 4.2.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. |