Ideabox
Ideabox Powerpack Addons FOR Elementor: vulnerabilidades y CVE
Ideabox Powerpack Addons FOR Elementor tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-5787 | Media (5.4) | 0.40% | — | 13 jun 2024 | The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's Link Effects widget in all… |
| CVE-2024-3668 | Alta (8.8) | 0.43% | — | 8 jun 2024 | The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a… |
| CVE-2024-5327 | Media (5.4) | 0.32% | — | 30 may 2024 | The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘pp_animated_gradient_bg_color’ parameter in all versions… |
| CVE-2024-2492 | Media (5.4) | 0.36% | — | 9 abr 2024 | The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Tweet widget in all versions up to, and including, 2.7.18 due to insufficient input sanitization and… |
| CVE-2024-2491 | Media (5.4) | 0.34% | — | 30 mar 2024 | The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the *_html_tag* attribute of multiple widgets in all versions up to, and including, 2.7.17 due to insufficient… |
| CVE-2024-1411 | Media (5.4) | 0.42% | — | 29 feb 2024 | The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the settings of the Twitter Buttons Widget in all versions up to, and including, 2.7.15 due to insufficient input… |
| CVE-2024-1055 | Media (5.4) | 0.42% | — | 7 feb 2024 | The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's buttons in all versions up to, and including, 2.7.14 due to… |
| CVE-2023-6984 | Media (4.3) | 0.20% | — | 3 ene 2024 | The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.13. This is due to missing or… |
| CVE-2023-49739 | Media (6.1) | 0.42% | — | 14 dic 2023 | Vulnerability in IdeaBox Creations PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a through 2.9.23. |
| CVE-2021-25027 | Media (6.1) | 0.88% | — | 3 ene 2022 | The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue |
| CVE-2021-24263 | Media (5.4) | 0.66% | — | 5 may 2021 | The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as… |