Wpmet
Wpmet Elementskit Elementor Addons: vulnerabilidades y CVE
Wpmet Elementskit Elementor Addons tiene 10 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-94500 | Media (6.5) | 0.17% | — | 23 sept 2026 | Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions. |
| CVE-2026-13393 | Baja (3.5) | 0.24% | — | 31 jul 2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the… |
| CVE-2026-13392 | Alta (7.2) | 0.66% | — | 31 jul 2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that… |
| CVE-2025-3614 | Media (5.4) | 0.27% | — | 24 jul 2025 | The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom widget in all versions up to, and including, 3.5.2 due to insufficient… |
| CVE-2025-4479 | Media (5.4) | 0.25% | — | 19 jun 2025 | The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin image comparison widget's before/after labels in all versions up to, and including, 3.5.2… |
| CVE-2024-11180 | Media (5.4) | 0.27% | — | 29 mar 2025 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to… |
| CVE-2025-0968 | Media (5.3) | 0.49% | — | 19 feb 2025 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content()… |
| CVE-2025-1005 | Media (5.4) | 0.36% | — | 15 feb 2025 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and including, 3.4.0 due to insufficient input… |
| CVE-2024-8546 | Media (5.4) | 0.44% | — | 25 sept 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and… |
| CVE-2023-6525 | Media (4.8) | 0.43% | — | 16 mar 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar element attributes in all versions up to, and including, 3.0.3 due to insufficient input… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Wpmet
Metform Elementor Contact Form Builder · 23Elements KIT Elementor Addons · 14Elementskit · 11WP Ultimate Review · 10Fundengine · 8Gutenkit · 7WP Social Login AND Register Social Counter · 5Elementskit Elementor Addons Lite · 2Elementskit Lite · 2WP Fundraising Donation AND Crowdfunding Platform · 1Shopengine · 1Metform · 1