Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total32
Critical2
High3
Medium27
Reset
Showing 1-20 of 32 records
Threat Entry Updated 2025-10-14

CVE-2025-9698 - Plus Addons For Elementor Plugin

The Plus Addons for Elementor WordPress plugin before 6.3.16 does not sanitize SVG file contents, which could allow users with minimum role access as Author to perform Stored Cross-Site Scripting attacks.

PLUGIN Plus Addons For Elementor

CVE-2025-9698

MEDIUM CVSS 6.8 2025-10-13
Threat Entry Updated 2025-03-24

CVE-2025-1287 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown, Syntax Highlighter, and Page Scroll widgets in all versions up to, and including, 6.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor

CVE-2025-1287

MEDIUM CVSS 6.4 2025-03-08
Threat Entry Updated 2025-02-04

CVE-2024-11829 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table Widget's searchable_label parameter in all versions up to, and including, 6.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor

CVE-2024-11829

MEDIUM CVSS 6.4 2025-02-01
Threat Entry Updated 2024-11-26

CVE-2024-10365 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.3 via the render function in modules/widgets/tp_carousel_anything.php, modules/widgets/tp_page_scroll.php, and other widgets. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

PLUGIN Plus Addons For Elementor

CVE-2024-10365

MEDIUM CVSS 4.3 2024-11-20
Threat Entry Updated 2025-02-05

CVE-2024-8913 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.11 via the render function in modules/widgets/tp_accordion.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

PLUGIN Plus Addons For Elementor

CVE-2024-8913

MEDIUM CVSS 4.3 2024-10-11
Threat Entry Updated 2024-09-27

CVE-2024-5583 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the carousel_direction parameter of testimonials widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor

CVE-2024-5583

MEDIUM CVSS 6.4 2024-08-22
Threat Entry Updated 2024-09-03

CVE-2024-6575 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘res_width_value’ parameter within the plugin's tp_page_scroll widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor

CVE-2024-6575

MEDIUM CVSS 6.4 2024-08-20
Threat Entry Updated 2024-09-03

CVE-2024-5763 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_date attribute within the plugin's Video widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor

CVE-2024-5763

MEDIUM CVSS 6.4 2024-08-20
Threat Entry Updated 2024-11-21

CVE-2024-4482 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied 'text_days' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor

CVE-2024-4482

MEDIUM CVSS 6.4 2024-07-03
Threat Entry Updated 2025-01-29

CVE-2024-4983 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘video_color’ parameter in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor

CVE-2024-4983

MEDIUM CVSS 6.4 2024-06-27
Threat Entry Updated 2024-11-21

CVE-2024-5455 - Plus Addons For Elementor Plugin

The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.5.4 via the 'magazine_style' parameter within the Dynamic Smart Showcase widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can…

PLUGIN Plus Addons For Elementor

CVE-2024-5455

HIGH CVSS 8.8 2024-06-21
Threat Entry Updated 2024-11-21

CVE-2024-5344 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘forgoturl’ attribute within the plugin's WP Login & Register widget in all versions up to, and including, 5.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Plus Addons For Elementor

CVE-2024-5344

MEDIUM CVSS 6.1 2024-06-21
Threat Entry Updated 2025-01-29

CVE-2024-5341 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' attribute of the Heading Title widget in all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor

CVE-2024-5341

MEDIUM CVSS 6.4 2024-05-30
Threat Entry Updated 2025-01-29

CVE-2024-4485 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_custom_attributes’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor

CVE-2024-4485

MEDIUM CVSS 6.4 2024-05-24
Threat Entry Updated 2025-01-29

CVE-2024-4484 - Plus Addons For Elementor Plugin

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘xai_username’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Plus Addons For Elementor

CVE-2024-4484

MEDIUM CVSS 6.4 2024-05-24
Threat Entry Updated 2025-02-03

CVE-2024-3718 - The Plus Addons For Elementor Plugin

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN The Plus Addons For Elementor

CVE-2024-3718

MEDIUM CVSS 6.4 2024-05-24
Threat Entry Updated 2025-01-29

CVE-2024-2784 - The Plus Addons For Elementor Plugin

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Hover Card widget in all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN The Plus Addons For Elementor

CVE-2024-2784

MEDIUM CVSS 6.4 2024-05-24
Threat Entry Updated 2025-01-27

CVE-2024-2785 - The Plus Addons For Elementor Plugin

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN The Plus Addons For Elementor

CVE-2024-2785

MEDIUM CVSS 6.4 2024-05-14
Threat Entry Updated 2025-01-27

CVE-2024-0445 - The Plus Addons For Elementor Plugin

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-34373 is likely a duplicate of this issue.

PLUGIN The Plus Addons For Elementor

CVE-2024-0445

MEDIUM CVSS 6.4 2024-05-14
Threat Entry Updated 2025-01-21

CVE-2024-3199 - The Plus Addons For Elementor Plugin

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN The Plus Addons For Elementor

CVE-2024-3199

MEDIUM CVSS 6.4 2024-05-02
Scroll to top