VendorsWebTechStreetelementor_addon_elementsall versions
Vulnerabilities

WebTechStreet Elementor Addon Elements 1.1 for WordPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2024-1358
Elementor Addon Elements <= 1.12.12 - Directory Traversal to Local File Inclusion
Published 2024-03-13 · Modified
8.8EPSS 0.012
CVE-2024-47361
WordPress Elementor Addon Elements plugin <= 1.13.6 - Broken Access Control vulnerability
Published 2024-11-01 · Modified
8.8EPSS 0.004
CVE-2024-30422
WordPress Elementor Addon Elements plugin <= 1.13.1 - Cross Site Scripting (XSS) vulnerability
Published 2024-03-28 · Modified
6.5EPSS 0.003
CVE-2024-29107
WordPress Elementor Addon Elements plugin <= 1.12.10 - Cross Site Scripting (XSS) vulnerability
Published 2024-03-19 · Modified
6.5EPSS 0.003
CVE-2024-47366
WordPress Elementor Addon Elements plugin <= 1.13.6 - Cross Site Scripting (XSS) vulnerability
Published 2024-10-06 · Modified
6.5EPSS 0.003
CVE-2024-3743
Elementor Addon Elements <= 1.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-05-02 · Modified
6.4EPSS 0.006
CVE-2024-0834
The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_to parameter in all versions up to, and including, 1.12.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published 2024-02-05 · Modified
6.4EPSS 0.005
CVE-2024-1392
Elementor Addon Elements <= 1.12.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Dual Button Widget
Published 2024-03-13 · Modified
6.4EPSS 0.005
CVE-2024-1393
Elementor Addon Elements <= 1.12.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Switcher Widget
Published 2024-03-13 · Modified
6.4EPSS 0.005
CVE-2024-1391
Elementor Addon Elements <= 1.12.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Thumbnail Slider Widget
Published 2024-03-13 · Modified
6.4EPSS 0.005
CVE-2024-1422
Elementor Addon Elements <= 1.12.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Modal Popup effet
Published 2024-03-13 · Modified
6.4EPSS 0.005
CVE-2024-2792
Elementor Addon Elements <= 1.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'Text Separator' and 'Image Compare' Widget
Published 2024-04-09 · Modified
6.4EPSS 0.005
CVE-2024-7122
Elementor Addon Elements <= 1.13.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
Published 2024-08-30 · Analyzed
6.4EPSS 0.004
CVE-2024-4569
Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-06-27 · Modified
6.4EPSS 0.004
CVE-2024-4401
Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via id and eae_slider_animation Parameters
Published 2024-08-30 · Analyzed
6.4EPSS 0.003
CVE-2024-4570
Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-06-27 · Modified
6.4EPSS 0.003
CVE-2021-24259
Elementor Addon Elements < 1.11.2 - Contributor+ Stored XSS
Published 2021-05-05 · Modified
5.4EPSS 0.006
CVE-2024-2091
Elementor Addon Elements <= 1.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-03-28 · Modified
5.4EPSS 0.005
CVE-2024-2092
Elementor Addon Elements <= 1.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Widget
Published 2024-06-12 · Modified
5.4EPSS 0.003
CVE-2023-4689
Elementor Addon Elements <= 1.12.7 - Cross-Site Request Forgery
Published 2023-11-15 · Modified
5.4EPSS 0.003
CVE-2023-4690
Elementor Addon Elements <= 1.12.7 - Cross-Site Request Forgery
Published 2023-11-15 · Modified
5.4EPSS 0.003
CVE-2023-4723
Elementor Addon Elements <= 1.12.7 - Missing Authorization to Sensitive Information Exposure
Published 2023-11-15 · Modified
5.3EPSS 0.009
CVE-2023-5381
Elementor Addon Elements <= 1.12.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
Published 2023-11-15 · Modified
4.8EPSS 0.005
CVE-2024-13215
Elementor Addon Elements <= 1.13.10 - Authenticated (Contributor+) Sensitive Information Exposure via Modal Popup
Published 2025-01-15 · Analyzed
4.3EPSS 0.005
CVE-2024-8902
Elementor Addon Elements <= 1.13.8 - Authenticated (Contributor+) Sensitive Information Exposure via table_saved_sections
Published 2024-10-12 · Analyzed
4.3EPSS 0.004