CVEs (25)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Webtechstreet 1Elementor Addon Elements Jun 17, 2026 Nov 15, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.12.7 due to insufficient input sanitization and output escaping. This...Show more |
1Webtechstreet 1Elementor Addon Elements Jun 17, 2026 Nov 15, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.12.7 via the ajax_eae_post_data function. This can allow unauthenticated attackers to...Show more |
1Webtechstreet 1Elementor Addon Elements Jun 17, 2026 Nov 15, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.12.7. This is due to missing or incorrect nonce validation on the eae_save_config function...Show more |
1Webtechstreet 1Elementor Addon Elements Jun 17, 2026 Nov 15, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.12.7. This is due to missing or incorrect nonce validation on the eae_save_elements functi...Show more |
1Webtechstreet 1Elementor Addon Elements Jun 17, 2026 May 5, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The “Elementor Addon Elements” WordPress Plugin before 1.11.2 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. |