{"error":0,"message":null,"data":{"name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor","plugin":"elementskit-lite","link":"https:\/\/wordpress.org\/plugins\/elementskit-lite\/","latest":"1788937980","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"ff5d0af1e218c7b6c52cc6e7e5ef48c3349431b44baae8fc12cffb5e42fb82b5","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 2.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24258","name":"CVE-2021-24258","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24258","description":"[en] The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.","date":"2021-05-05"},{"id":"b8ce10d9338eacdf9c3dddfae2b475e049401306","name":"Elements Kit Lite\/Pro <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elements-kit-litepro-217-authenticated-contributor-stored-cross-site-scripting","description":"The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.","date":"2021-04-13"},{"id":"47b47b86-899b-4de3-8a3c-2d5d1774298f","name":"ElementsKit and ElementsKit Pro &lt; 2.2.0 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/47b47b86-899b-4de3-8a3c-2d5d1774298f","description":"The Elements kit lite and Elements kit pro WordPress Plugins &lt; 2.2.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.\r\n\r\nThe &ldquo;fun fact&rdquo; widget accepts an &ldquo;ekit_funfact_title_size&rdquo; parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a &lsquo;save_builder&rsquo; request containing JavaScript in the &lsquo;ekit_funfact_title_size&rsquo; parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.\r\n\r\nThe heading widget (includes\/widgets\/heading.php) accepts &lsquo;ekit_heading_title_tag&rsquo; and &lsquo;ekit_heading_sub_title_tag&rsquo; parameters. When sending a &lsquo;save_builder&rsquo; request, these parameters can be set to &lsquo;script&rsquo; and combined with the &lsquo;ekit_heading_title&rsquo; or &lsquo;ekit_heading_sub_title&rsquo; parameters containing JavaScript - although the &lsquo;ekit_heading_sub_title&rsquo; parameter is escaped, this is trivial to overcome since the actual scripting tags are added in the &lsquo;ekit_heading_sub_title_tag&rsquo;.\r\n\r\nThe icon box (includes\/widgets\/icon-box.php) widget accepts a &lsquo;ekit_icon_box_title_size&rsquo; parameter. It is possible to send a modified &lsquo;save_builder&rsquo; request containing JavaScript in the &lsquo;ekit_icon_box_title_size&rsquo; parameter for this widget,  which is not filtered and is output without escaping. \r\n\r\nSimilarly, the image box (widgets\/image-box\/image-box.php) widget accepts an &lsquo;ekit_image_box_title_size&rsquo; parameter. It is possible to send a modified &lsquo;save_builder&rsquo; request containing JavaScript in the &lsquo;ekit_image_box_title_size&rsquo; parameter for this widget,  which is not filtered and is output without escaping. \r\n\r\nThe pricing (widgets\/pricing\/pricing.php) widget accepts a &lsquo;ekit_pricing_title_size&rsquo; parameter. When sending a &lsquo;save_builder&rsquo; request, it is possible to set the &lsquo;ekit_pricing_title_size&rsquo; parameter to &lsquo;script&rsquo; and populate the &lsquo;ekit_pricing_table_title&rsquo; parameter with Javascript - although the &lsquo;ekit_pricing_table_title&rsquo; parameter is escrped, this is trivial to overcome since the actual script tag is added in the &lsquo;ekit_pricing_title_size&rsquo; parameter.\r\n\r\nFinally, impacting the pro version only, the motion text (widgets\/motion-text\/motion-text.php) widget accepts a &lsquo;ekit_motion_text_sub_title_tag&rsquo; parameter. It is possible to send a &lsquo;save_builder&rsquo; request containing JavaScript in the &lsquo;ekit_motion_text_sub_title_tag&rsquo; parameter, which is not filtered and is output without escaping. \r\n\r\nEach of these issues can be abused by a lower-privileged user, such as a contributor, to add malicious JavaScript to a post, which would then be executed in the browser of any user previewing that post. It is common for administrators or editors to preview the posts of users without publishing permissions before publishing their content.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"554208971d931b57e1bedb9e3e3ed2399d693ac58bffa57c6a08095be80fac59","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 2.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3e7dadf8a278ee988119f623806d9eacd4e85b75","name":"WordPress Elements kit Elementor addons plugin <= 2.1.7 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elements-kit-elementor-addons-plugin-2-1-7-multiple-authenticated-stored-cross-site-scripting-xss-vulnerabilities","description":"Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress Elements kit Elementor addons plugin (versions <= 2.1.7).","date":"2021-04-13"}],"impact":[]},{"uuid":"644f25c21b5012b42f0ac3a91f61e09385d7d53579336e11f2d32bb774cf4d11","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 2.9.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-39993","name":"CVE-2023-39993","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-39993","description":"[en] Missing Authorization vulnerability in Wpmet Elements kit Elementor addons.This issue affects Elements kit Elementor addons: from n\/a through 2.9.0.","date":"2024-06-19"},{"id":"03ffe88b9fee2e3f96088d520f349c59177d982c","name":"WordPress  Elements kit Elementor addons Plugin  <= 2.9.0 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-lite-plugin-2-9-0-broken-access-control-vulnerability","description":"On June 24, 2023, the vendor confirmed they would provide a patch. No patched version is available.\nRafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress Elements kit Elementor addons Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has not been known to be fixed yet.","date":"2023-08-23"},{"id":"ac889e63f7e838dade5b0bab0fca5221c1d4a401","name":"Elements kit Elementor addons <= 2.9.1 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elements-kit-elementor-addons-291-missing-authorization","description":"The Elements kit Elementor addons plugin for WordPress is vulnerable to unauthorized admin notice dismissal due to a missing capability check on the dismiss_ajax_call function in versions up to, and including, 2.9.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss notices intended for admins. Version 2.9.1 addresses this while version 2.9.2 ensures these notices can only be viewed by admins.","date":"2023-08-23"},{"id":"e9dda50c-b2f6-4fbe-8e40-5aff175b8916","name":"Elements kit Elementor addons &lt; 2.9.2 - Missing Authorization","link":"https:\/\/wpscan.com\/vulnerability\/e9dda50c-b2f6-4fbe-8e40-5aff175b8916","description":"The plugin is vulnerable to unauthorized admin notice dismissal due to a missing capability check on the dismiss_ajax_call function, making it possible for authenticated attackers, with subscriber-level access and above, to dismiss notices intended for admins.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5a2cc601574c9e3d2dd1a80b580965727bab16444a0bcd22973c1fcfd4f1c765","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6582","name":"CVE-2023-6582","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6582","description":"[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to obtain contents of posts in draft, private or pending review status that should not be visible to the general public. This applies to posts created with Elementor only.","date":"2024-01-11"},{"id":"16a374efb7c5af9f9a143449a78887c7527d051b","name":"ElementsKit Lite <= 3.0.3 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-lite-303-unauthenticated-sensitive-information-exposure","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to obtain contents of posts in draft, private or pending review status that should not be visible to the general public. This applies to posts created with Elementor only.","date":"2024-01-08"},{"id":"7cf5ec596234fa36c4fb6ae9835047bf42821ce6","name":"WordPress  Elements kit Elementor addons Plugin  <= 3.0.3 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-lite-plugin-3-0-3-unauthenticated-sensitive-information-exposure-vulnerability","description":"Update the WordPress Elements kit Elementor addons plugin to the latest available version (at least 3.0.4).\nNex Team discovered and reported this Sensitive Data Exposure vulnerability in WordPress Elements kit Elementor addons Plugin.  This vulnerability has been fixed in version 3.0.4.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-08"},{"id":"f42f0003-fc64-44b7-8461-73208ec1862d","name":"ElementsKit Lite &lt; 3.0.4 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/wpscan.com\/vulnerability\/f42f0003-fc64-44b7-8461-73208ec1862d","description":"The plugin is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to obtain contents of posts in draft, private or pending review status that should not be visible to the general public. This applies to posts created with Elementor only.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"82fef6d8188755ed8d643a2d7a476d6c05be0e141ee813a20a41a7dc856ea952","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.0.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2042","name":"CVE-2024-2042","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2042","description":"[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-16"},{"id":"c5932730e71d0ee18d455df45b0362e2e66afb71","name":"ElementsKit Elementor addons <= 3.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-305-authenticated-contributor-stored-cross-site-scripting-via-image-accordion-widget","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-15"},{"id":"f6676e99e531fae51ad24fe55a572c89b669fd59","name":"WordPress  Elements kit Elementor addons Plugin    <= 3.0.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-elementor-addons-plugin-3-0-5-authenticated-contributor-stored-cross-site-scripting-via-image-accordion-widget-vulnerability","description":"Update the WordPress Elements kit Elementor addons plugin to the latest available version (at least 3.0.6).\nwesley (wcraft) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elements kit Elementor addons Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.0.6.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"9e5e648b-ac9f-43ae-8239-6f3b85b0634a","name":"ElementsKit Elementor addons &lt; 3.0.6 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/9e5e648b-ac9f-43ae-8239-6f3b85b0634a","description":"The plugin does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9c5073ee742f0f9d25ce1650c3ea25a484f7581f40826112aba48bbe0978f19c","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.0.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1239","name":"CVE-2024-1239","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1239","description":"[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blog post read more button in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-16"},{"id":"83efc02925adb0c92251397a0bc7100943b77b45","name":"ElementsKit Elementor addons <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-304-authenticated-contributor-stored-cross-site-scripting","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blog post read more button in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-15"},{"id":"2970d32527943582b39d11bab6a0c3021ee996e8","name":"WordPress  Elements kit Elementor addons Plugin    <= 3.0.4 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-elementor-addons-plugin-3-0-4-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Elements kit Elementor addons plugin to the latest available version (at least 3.0.5).\nRandomRoot discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elements kit Elementor addons Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.0.5.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"3841d9e2-075e-415f-aa6d-e45bd9769cd5","name":"ElementsKit Elementor addons &lt; 3.0.5 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/3841d9e2-075e-415f-aa6d-e45bd9769cd5","description":"The plugin does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4f95e91752b3bd1f2d7a8a8817466f392d8a782c4030377381424d7d4241f33a","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6525","name":"CVE-2023-6525","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6525","description":"[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar element attributes in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This primarily affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-03-16"},{"id":"bf9b2d72897b4d9aafeda53e66601aa808a80bf8","name":"ElementsKit Elementor addons <= 3.0.3 - Authenticated(Editor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-303-authenticatededitor-stored-cross-site-scripting","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar element attributes in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This primarily affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-03-15"},{"id":"e81c341ddde5b821b05cfeb7350c920b85285689","name":"WordPress  Elements kit Elementor addons Plugin    <= 3.0.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-elementor-addons-plugin-3-0-3-authenticated-editor-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Elements kit Elementor addons plugin to the latest available version (at least 3.0.4).\nUlyses Saicha discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elements kit Elementor addons Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.0.4.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"42138348-d9a0-439f-8e65-3d3878e9fc65","name":"ElementsKit Elementor addons &lt; 3.0.4 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/42138348-d9a0-439f-8e65-3d3878e9fc65","description":"The plugin does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b792c9e41734fdb04633006281cda61b5aba5e3901320c619e8476e3fb21c529","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.0.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1238","name":"CVE-2024-1238","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1238","description":"[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button ID parameter in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-30"},{"id":"11f6863d4d3058f9c4212e4188dbf68284d0b17c","name":"ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-306-authenticated-contributor-stored-cross-site-scripting","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button ID parameter in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32505 is likely a duplicate of this issue.","date":"2024-03-29"},{"id":"1cb0ca3018adc35e199213def25991563a08c4b4","name":"WordPress  Elements kit Elementor addons Plugin    <= 3.0.6 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-elementor-addons-plugin-3-0-6-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Elements kit Elementor addons plugin to the latest available version (at least 3.0.7).\nwesley (wcraft) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elements kit Elementor addons Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.0.7.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"65ffbfb5-491a-43d2-930b-e27a528a2f33","name":"ElementsKit Elementor addons &lt; 3.0.7 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/65ffbfb5-491a-43d2-930b-e27a528a2f33","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the button ID parameter due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8ec60d0619df03b9005de821880d9644b0a9dc8d0eda4ec79aedaa9aef193d53","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.0.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2047","name":"CVE-2024-2047","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2047","description":"[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the render_raw function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other \u201csafe\u201d file types can be uploaded and included.","date":"2024-03-30"},{"id":"e4bb4ddd3123f428f14e19cca6be169d6b6454da","name":"ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Local File Inclusion in render_raw","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-306-authenticated-contributor-local-file-inclusion-in-render-raw","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the render_raw function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other \u201csafe\u201d file types can be uploaded and included.","date":"2024-03-29"},{"id":"7ba01bc3daf4db51357cd6988664a4f222183e4a","name":"WordPress  Elements kit Elementor addons Plugin    <= 3.0.6 is vulnerable to Local File Inclusion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-elementor-addons-plugin-3-0-6-authenticated-contributor-local-file-inclusion-in-render-raw-vulnerability","description":"Update the WordPress Elements kit Elementor addons plugin to the latest available version (at least 3.0.7).\nwesley (wcraft) discovered and reported this Local File Inclusion vulnerability in WordPress Elements kit Elementor addons Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potentially allow complete database takeover depending on the configuration. This vulnerability has been fixed in version 3.0.7.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"78b15554-090d-4092-bf7a-02fb61901215","name":"ElementsKit Elementor addons &lt; 3.0.7 - Contributor+ Local File Inclusion","link":"https:\/\/wpscan.com\/vulnerability\/78b15554-090d-4092-bf7a-02fb61901215","description":"The plugin is vulnerable to Local File Inclusion via the render_raw function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other &ldquo;safe&rdquo; file types can be uploaded and included.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-98","name":"Improper Control of Filename for Include\/Require Statement in PHP Program ('PHP Remote File Inclusion')","description":"The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in \"require,\" \"include,\" or similar functions."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"6ed7634d3c5a85bbbed2553aa646e59c7e5d5bb3633d0308fa032dc3359691fb","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2803","name":"CVE-2024-2803","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2803","description":"[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-04"},{"id":"c0b2dbad0a3f6b60365e7b753b9602f40a2647a2","name":"ElementsKit Elementor addons <= 3.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-307-authenticated-contributor-stored-cross-site-scripting-via-countdown-widget","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-03"},{"id":"19edf214498a0e117e38ada94d527d9cd95ab05f","name":"WordPress  Elements kit Elementor addons Plugin    <= 3.0.7 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-elementor-addons-plugin-3-0-7-authenticated-contributor-stored-cross-site-scripting-via-countdown-widget-vulnerability","description":"Update the WordPress Elements kit Elementor addons plugin to the latest available version (at least 3.1.0).\nWebbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Elements kit Elementor addons Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.1.0.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b4d0995a73e9b7bca05615acc9de34d640e90e2b5999b15c37aabdc2d005c0a8","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.0.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-32505","name":"CVE-2024-32505","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-32505","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor ElementsKit Elementor addons Lite elementskit-lite.This issue affects ElementsKit Elementor addons Lite: from n\/a through <= 3.0.6.","date":"2024-04-17"},{"id":"a49ae22b7f2579f9d2fef23e0a8adddc44240a9f","name":"WordPress Elements kit Elementor addons Plugin <= 3.0.6 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-elementor-addons-plugin-3-0-6-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Elements kit Elementor addons Plugin <= 3.0.6 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Elements kit Elementor addons<\/p><p>Link: https:\/\/wordpress.org\/plugins\/elementskit-lite\/#developers<\/p><p>Affected Version <= 3.0.6<\/p><p>Fixed in version 3.0.7 <\/p>","date":"2024-04-15"},{"id":"EUVD-2024-30307","name":"EUVD-2024-30307","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-30307","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Elements kit Elementor addons allows Stored XSS.This issue affects Elements kit Elementor addons: from n\/a through 3.0.6.","date":"2024-04-17"},{"id":"2b532cf8379bb576170b9d04f367c99be43e7b3e","name":"ElementsKit Elementor addons Lite <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-lite-306-authenticated-contributor-stored-cross-site-scripting","description":"The ElementsKit Elementor addons Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"7ef80abfb000a6f498e6d498f854f6334f22c942bd12b12bedd26fd0bcb7705a","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3499","name":"CVE-2024-3499","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3499","description":"[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the generate_navigation_markup function of the Onepage Scroll module. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other \u201csafe\u201d file types can be uploaded and included.","date":"2024-05-02"},{"id":"9a17df95a2982662e210b0fd45dce57f6f0dc890","name":"ElementsKit Elementor addons <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Module","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-310-authenticated-contributor-local-file-inclusion-via-onepage-scroll-module","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the generate_navigation_markup function of the Onepage Scroll module. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other \u201csafe\u201d file types can be uploaded and included.","date":"2024-04-22"},{"id":"fc37d6b93c90635dc8fbed72fd6a9bc3e427901c","name":"WordPress Elements kit Elementor addons Plugin <= 3.1.0 is vulnerable to Local File Inclusion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-elementor-addons-plugin-3-1-0-authenticated-contributor-local-file-inclusion-via-onepage-scroll-module-vulnerability","description":"<p>WordPress Elements kit Elementor addons Plugin <= 3.1.0 is vulnerable to Local File Inclusion<\/p><p>Software: Elements kit Elementor addons<\/p><p>Link: https:\/\/wordpress.org\/plugins\/elementskit-lite\/#developers<\/p><p>Affected Version <= 3.1.0<\/p><p>Fixed in version 3.1.1 <\/p>","date":"2024-04-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-98","name":"Improper Control of Filename for Include\/Require Statement in PHP Program ('PHP Remote File Inclusion')","description":"The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in \"require,\" \"include,\" or similar functions."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"3960ad23cbb0b1118c2b370d730d5decc8c881b886ecf6c06a6c1fe5945c2b38","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3650","name":"CVE-2024-3650","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3650","description":"[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions 3.0.7 through 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-02"},{"id":"d492e77255d133bca930e214786ac8480c790c8f","name":"ElementsKit Elementor addons 3.0.7 - 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-307-312-authenticated-contributor-stored-cross-site-scripting-via-image-accordion-widget","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions 3.0.7 through 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-30"},{"id":"32056ce96dbb3ceae72182a8c3e4b472bfe433d7","name":"WordPress Elements kit Elementor addons Plugin <= 3.1.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-elementor-addons-plugin-3-1-2-authenticated-contributor-stored-cross-site-scripting-via-image-accordion-widget-vulnerability","description":"<p>WordPress Elements kit Elementor addons Plugin <= 3.1.2 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Elements kit Elementor addons<\/p><p>Link: https:\/\/wordpress.org\/plugins\/elementskit-lite\/#developers<\/p><p>Affected Version <= 3.1.2<\/p><p>Fixed in version 3.1.3 <\/p>","date":"2024-05-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9d00c665da40a5017b5bcc463c775c6a4fe0524b680c23852d1488a94c91b90e","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-37255","name":"CVE-2024-37255","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-37255","description":"[en] Missing Authorization vulnerability in Roxnor ElementsKit Elementor addons Lite elementskit-lite.This issue affects ElementsKit Elementor addons Lite: from n\/a through <= 3.1.4.","date":"2024-11-01"},{"id":"dfda7ef94014e229855da8dfda083088bba2c5b7","name":"WordPress Elements kit Elementor addons Plugin <= 3.1.4 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-lite-plugin-3-1-4-unauthenticated-broken-access-control-vulnerability","description":"<p>WordPress Elements kit Elementor addons Plugin <= 3.1.4 is vulnerable to Broken Access Control<\/p><p>Software: Elements kit Elementor addons<\/p><p>Link: https:\/\/wordpress.org\/plugins\/elementskit-lite\/#developers<\/p><p>Affected Version <= 3.1.4<\/p><p>Fixed in version 3.2.0 <\/p>","date":"2024-06-27"},{"id":"56beeee9baa5ab6c70921b36ac061a446b59ff7c","name":"Elements kit Elementor addons <= 3.1.4 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elements-kit-elementor-addons-314-missing-authorization","description":"The Elements kit Elementor addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor() function in versions up to, and including, 3.1.4. This makes it possible for unauthenticated attackers to update post data.","date":"2024-06-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"31bd098379c3765e1ff78e5432fa4a9e1bdc804cea2c79ad69383bb481375168","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6455","name":"CVE-2024-6455","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6455","description":"[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, pending and private items.","date":"2024-07-18"},{"id":"6ed2a8c58b0db0f997f28138869ed52025634b95","name":"WordPress Elements kit Elementor addons Plugin <= 3.2.0 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-elementor-addons-plugin-3-2-0-unauthenticated-information-exposure-via-ekit-widgetarea-content-function-vulnerability","description":"<p>WordPress Elements kit Elementor addons Plugin <= 3.2.0 is vulnerable to Sensitive Data Exposure<\/p><p>Software: Elements kit Elementor addons<\/p><p>Link: https:\/\/wordpress.org\/plugins\/elementskit-lite\/#developers<\/p><p>Affected Version <= 3.2.0<\/p><p>Fixed in version 3.2.1 <\/p>","date":"2024-07-18"},{"id":"86b90430597cabe444c5a156feee5be5bbe5e429","name":"ElementsKit Elementor addons <= 3.2.0 - Unauthenticated Information Exposure via ekit_widgetarea_content Function","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-320-unauthenticated-information-exposure-via-ekit-widgetarea-content-function","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, pending and private items.","date":"2024-07-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2e5ba96f2077b00147c66b264e5e25b5217197a429d3c149c0fa95a087137fa1","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.2.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8546","name":"CVE-2024-8546","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8546","description":"[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-09-25"},{"id":"83c045cef6a0bdd6febee159a9c9cad4b03e9661","name":"WordPress Elements kit Elementor addons Plugin <= 3.2.7 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-elementor-addons-plugin-3-2-7-authenticated-contributor-stored-cross-site-scripting-via-video-widget-vulnerability","description":"<p>WordPress Elements kit Elementor addons Plugin <= 3.2.7 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Elements kit Elementor addons<\/p><p>Link: https:\/\/wordpress.org\/plugins\/elementskit-lite\/#developers<\/p><p>Affected Version <= 3.2.7<\/p><p>Fixed in version 3.2.8 <\/p>","date":"2024-09-25"},{"id":"e867c98a5902d06ab2f38114d8428e350cdb6669","name":"ElementsKit Elementor addons <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-327-authenticated-contributor-stored-cross-site-scripting-via-video-widget","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-09-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8b9faf7d847f8b592810edba2b5dfc720ac249e2023663840458b20693a5e0fe","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.3.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10091","name":"CVE-2024-10091","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10091","description":"[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-10-26"},{"id":"8003cf06c2ad93ca13155f5fab0f407e4b959e9b","name":"ElementsKit Elementor addons <= 3.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-329-authenticated-contributor-stored-cross-site-scripting-via-image-comparison-widget","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-10-25"},{"id":"31987cf11d07f42c3af7b5f8f7940404e9b0a6dc","name":"WordPress Elements kit Elementor addons Plugin <= 3.2.9 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-elementor-addons-plugin-3-2-9-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Elements kit Elementor addons Plugin <= 3.2.9 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Elements kit Elementor addons<\/p><p>Link: https:\/\/wordpress.org\/plugins\/elementskit-lite\/#developers<\/p><p>Affected Version <= 3.2.9<\/p><p>Fixed in version 3.3.0 <\/p>","date":"2024-10-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"927a4a78f37e91624e20ca83a21a7eae467f0d995df94d90bfc35691b77ebd6d","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-1005","name":"ElementsKit Elementor addons <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-1005","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"cf0d775c2fe197a491a0970e0a7168f0186d7522","name":"WordPress Elements kit Elementor addons Plugin <= 3.4.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/elementskit-lite\/vulnerability\/wordpress-elementskit-elementor-addons-plugin-3-4-0-authenticated-contributor-stored-cross-site-scripting-via-image-accordion-widget-vulnerability","description":"<p>WordPress Elements kit Elementor addons Plugin <= 3.4.0 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Elements kit Elementor addons<\/p><p>Fixed in version 3.4.1 <\/p><p>Affected Version <= 3.4.0<\/p><p>CVE: CVE-2025-1005<\/p>","date":"2025-02-14"},{"id":"670aee88b8b310d4ca48f57b9124e63c7bda19d1","name":"ElementsKit Elementor addons <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-340-authenticated-contributor-stored-cross-site-scripting-via-image-accordion-widget","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-02-14"},{"id":"EUVD-2025-1963","name":"EUVD-2025-1963","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-1963","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-02-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"c1be7cd1b64cb31ffd0163467bba7370b01f8165f80fdd40a3baa1e30094a371","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-0968","name":"ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-0968","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0  due to a missing capability checks on the get_megamenu_content() function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, trashed and private items.","date":"0000-00-00"},{"id":"738e1f09d57f379faf9647c9f7ab9afc616aacee","name":"ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-340-unauthenticated-information-exposure-via-get-megamenu-content-function","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0  due to a missing capability checks on the get_megamenu_content() function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, trashed and private items.","date":"2025-02-18"},{"id":"EUVD-2025-4703","name":"EUVD-2025-4703","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-4703","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0  due to a missing capability checks on the get_megamenu_content() function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, trashed and private items.","date":"2025-02-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"2a07939f2a8c257e49e85134e85ed778c876cc68d092c32135d2d032681a0da7","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.4.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-11180","name":"CVE-2024-11180","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-11180","description":"[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-03-29"},{"id":"55aa78e6f2a668e6f5e82b5a999561018c84900d","name":"ElementsKit Elementor addons <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-347-authenticated-contributor-stored-cross-site-scripting","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-03-28"},{"id":"EUVD-2024-54336","name":"EUVD-2024-54336","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-54336","description":"The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-03-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f27ac7133ecd6f589f3924440fec9f11c4c20603e7d7ccb238316f5405d6c9b3","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-4479","name":"ElementsKit Lite <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-4479","description":"The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin image comparison widget's before\/after labels in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"934a4a8d5de14c5c5ce96df874cefdeae042232d","name":"ElementsKit Lite <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-lite-352-authenticated-contributor-stored-cross-site-scripting-via-image-comparison-widget","description":"The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin image comparison widget's before\/after labels in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-18"},{"id":"EUVD-2025-18679","name":"EUVD-2025-18679","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-18679","description":"The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin image comparison widget's before\/after labels in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5c502a095fa968c2eb82077be12f2b8074c257672c20abb23e76f77dcf72ffc1","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-3614","name":"ElementsKit Elementor Addons and Templates <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-3614","description":"The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom widget in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"c40d9e473c16729b19db527ef1735570815257d8","name":"ElementsKit Elementor Addons and Templates <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-and-templates-352-authenticated-contributor-stored-cross-site-scripting-via-custom-widget","description":"The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom widget in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-07-24"},{"id":"EUVD-2025-22550","name":"EUVD-2025-22550","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-22550","description":"The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom widget in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-07-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"41e919784a419c965b13366972a02e529fb58475078bef0aa7323323830d63dc","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.7.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-23693","name":"CVE-2026-23693","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-23693","description":"[en] ElementsKit Elementor Addons \u2013 Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint \/wp-json\/elementskit\/v1\/widget\/mailchimp\/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API credentials and insufficiently validates certain parameters, including the list parameter, when constructing upstream Mailchimp API requests. An unauthenticated attacker can abuse the endpoint as an open proxy to Mailchimp, potentially triggering unauthorized API calls, manipulating subscription data, exhausting API quotas, or causing resource consumption on the affected WordPress site.","date":"2026-02-23"},{"id":"36dd6664421f1c76bcaa50888eb02580550ba51c","name":"ElementsKit Elementor addons Lite < 3.7.9 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-lite-379-missing-authorization","description":"The ElementsKit Elementor addons Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 3.7.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-02-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"h","a":"h","score":"10.0","severity":"c","exploitable":"3.9","impact":"6.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:H\/A:H","score":"10.0","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"high","a":"high","exploitable":"3.9","impact":"6.0"},"cwe":[{"cwe":"CWE-306","name":"Missing Authentication for Critical Function","description":"The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"bfad84da320299480e3eac48b4c10d83e35bb57e9ae6b3d8ab9b45d5ebd5af2a","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.8.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-2600","name":"ElementsKit Elementor Addons and Templates <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Simple Tab Widget","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2600","description":"The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ekit_tab_title' parameter in the Simple Tab widget in all versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"2e6af0743a7c83cc632c47284649e76b942fb897","name":"ElementsKit Elementor Addons and Templates <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Simple Tab Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-and-templates-379-authenticated-contributor-stored-cross-site-scripting-via-simple-tab-widget","description":"The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ekit_tab_title' parameter in the Simple Tab widget in all versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-04-03"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"10d36ecd0b1cc31f0b6b3b4e2037887086e9f251cbda761d026df163a28e6247","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.9.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.9.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-4362","name":"CVE-2026-4362","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-4362","description":"[en] The ElementsKit Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `Live_Action::reset()` function in all versions up to, and including, 3.8.2 The function is hooked to the WordPress `init` action and triggers when both `post` and `action=elementor` GET parameters are present, with no authentication or nonce verification. This makes it possible for unauthenticated attackers to overwrite the Elementor content (`_elementor_data`) of any `elementskit_widget` custom post type by visiting a specially crafted URL. The widget's custom designs, text, and configurations are permanently replaced with a blank template.","date":"2026-05-05"},{"id":"924b2d1a18d59d5d49eefab6da8d10bb2a8ff0b9","name":"ElementsKit Elementor Addons <= 3.8.2 - Missing Authorization to Unauthenticated Widget Content Overwrite","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-382-missing-authorization-to-unauthenticated-widget-content-overwrite","description":"The ElementsKit Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `Live_Action::reset()` function in all versions up to, and including, 3.8.2 The function is hooked to the WordPress `init` action and triggers when both `post` and `action=elementor` GET parameters are present, with no authentication or nonce verification. This makes it possible for unauthenticated attackers to overwrite the Elementor content (`_elementor_data`) of any `elementskit_widget` custom post type by visiting a specially crafted URL. The widget's custom designs, text, and configurations are permanently replaced with a blank template.","date":"2026-05-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3dc99afaa28e54462a69da7ea30501a60c96b71d67c490c77045ee7db6272bd1","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.9.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.9.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-49053","name":"CVE-2026-49053","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-49053","description":"[en] Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects ElementsKit Elementor addons Lite: from n\/a through 3.9.6.","date":"2026-05-27"},{"id":"2c35b8b85dc88f71a52e9703ebd816d16c3ab2d0","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets & Templates Addons for Elementor <= 3.9.6 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/fa8a1e98-8e5b-49d3-8378-f7b5be92f205","description":"The ElementsKit Elementor Addons \u2013 Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-05-27"},{"id":"865197b8132e06a5014879c9bde4039cc4060377","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets & Templates Addons for Elementor <= 3.9.6 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-advanced-widgets-templates-addons-for-elementor-396-missing-authorization","description":"The ElementsKit Elementor Addons \u2013 Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-05-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"89cb97ec619993d09080c7dc912a58d62275fdde8b26ca58ea9af7136881eb25","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.9.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.9.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-49052","name":"CVE-2026-49052","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-49052","description":"[en] Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects ElementsKit Elementor addons Lite: from n\/a through 3.9.6.","date":"2026-05-27"},{"id":"4017e8edde6f849022190ab892f0a468863fe1fb","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets & Templates Addons for Elementor <= 3.9.6 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/6f1345b0-a43e-475f-9d19-78600f17b8e6","description":"The ElementsKit Elementor Addons \u2013 Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.6. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.","date":"2026-05-27"},{"id":"05e53fa568b32c39c6f156cc2eb9f5ecfd935f98","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets & Templates Addons for Elementor <= 3.9.6 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-advanced-widgets-templates-addons-for-elementor-396-missing-authorization-2","description":"The ElementsKit Elementor Addons \u2013 Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.6. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.","date":"2026-05-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"401bfe003fb77a8261755b962cf5ae2d9023f1ad6829946f93453138e0024deb","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.10.01","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.01","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-13393","name":"CVE-2026-13393","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-13393","description":"[en] The ElementsKit Elementor Addons  WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.","date":"2026-07-31"},{"id":"a14f61bec3203856bb1baa4a3bd976e41b3827e7","name":"ElementsKit Lite <= 3.10.0 - Authenticated (Subsite administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-lite-3100-authenticated-subsite-administrator-stored-cross-site-scripting","description":"The ElementsKit Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subsite administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-14"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"399ab8578a5a0a2de0074deddbf3f6cc4536268236a6821ec0b9d8d62361d0a9","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets &amp; Templates Addons for Elementor [elementskit-lite] < 3.10.01","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.01","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-13392","name":"CVE-2026-13392","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-13392","description":"[en] The ElementsKit Elementor Addons  WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons  WordPress plugin before 3.10.01 subsequently executes, allowing arbitrary PHP code to run on the server; on a multisite network this lets a non-super subsite Administrator, who is otherwise denied code\/file editing, reach host-level code execution beyond the privileges the network grants them.","date":"2026-07-31"},{"id":"00ecca4f324fb1316e1b7f3ea191258f24252e3e","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets & Templates Addons for Elementor < 3.10.01 - Authenticated (Admin+) Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/ce5c048a-0dbf-448d-bfca-aff347d9466b","description":"The ElementsKit Elementor Addons \u2013 Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 3.10.01 (exclusive). This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.","date":"2026-08-04"},{"id":"3496d3ff9e21dfdb6ebf7c16c9a3727170074758","name":"ElementsKit Elementor Addons \u2013 Advanced Widgets & Templates Addons for Elementor < 3.10.01 - Authenticated (Admin+) Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/elementskit-lite\/elementskit-elementor-addons-advanced-widgets-templates-addons-for-elementor-31001-authenticated-admin-remote-code-execution","description":"The ElementsKit Elementor Addons \u2013 Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 3.10.01 (exclusive). This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.","date":"2026-05-27"}],"impact":{"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}}]},"updated":"1786948388"}