{"error":0,"message":null,"data":{"name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets","plugin":"essential-addons-for-elementor-lite","link":"https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/","latest":"1789537380","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"479cedce61f3c9651dbd2ee99e1fda98764f50dfea519037e328f90b9ec16ad7","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.0.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.0.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0683","name":"CVE-2022-0683","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0683","description":"[en] The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the settings parameter found in the ~\/includes\/Traits\/Helper.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 5.0.8.","date":"2022-02-24"},{"id":"e135a9bff4fb1c28b76f0f8ff193a37b7e16d30a","name":"WordPress Essential Addons for Elementor plugin <= 5.0.8 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-0-8-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by Pham Van Khanh (rskvp93) from VCSLab of Viettel Cyber Security & Nguyen Dinh Bien (biennd4) from VCSLab of Viettel Cyber Security in WordPress Essential Addons for Elementor plugin (versions <= 5.0.8).","date":"2022-02-18"},{"id":"7744ffce1ff5002a02b26800ef7a615c0d85a2b2","name":"Essential Addons for Elementor Lite <= 5.0.8 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-lite-508-reflected-cross-site-scripting","description":"The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the settings parameter found in the ~\/includes\/Traits\/Helper.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 5.0.8.","date":"2022-02-18"},{"id":"9ea3248d-8320-465f-bf31-4365148b4b56","name":"Essential Addons for Elementor Lite &lt; 5.0.9 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/9ea3248d-8320-465f-bf31-4365148b4b56","description":"The plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the settings parameter found in the ~\/includes\/Traits\/Helper.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ba391c252e9ad7a85f73c2a07d3d3ec522f22adfd583832384cea619a24dcb18","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.0.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.0.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0320","name":"CVE-2022-0320","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0320","description":"[en] The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server, this could also lead to RCE via user uploaded files or other LFI to RCE techniques.","date":"2022-02-01"},{"id":"31853a8fd243d362166d927ccf1f3e4c965b88fc","name":"WordPress Essential Addons for Elementor plugin <= 5.0.4 - Unauthenticated Local File Inclusion (LFI) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-0-4-unauthenticated-local-file-inclusion-lfi-vulnerability","description":"Unauthenticated Local File Inclusion (LFI) vulnerability discovered by Wai Yan Myo Thet in WordPress Essential Addons for Elementor plugin (versions <= 5.0.4).","date":"2022-01-31"},{"id":"f85d567a02e4f0ca4ca8de703f9d905584da0137","name":"Essential Addons for Elementor  <= 5.0.4 - Local File Inclusion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-504-local-file-inclusion","description":"The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server, this could also lead to RCE via user uploaded files or other LFI to RCE techniques.","date":"2022-01-21"},{"id":"0d02b222-e672-4ac0-a1d4-d34e1ecf4a95","name":"Essential Addons for Elementor &lt; 5.0.5 - Unauthenticated LFI","link":"https:\/\/wpscan.com\/vulnerability\/0d02b222-e672-4ac0-a1d4-d34e1ecf4a95","description":"The plugin does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server, this could also lead to RCE via user uploaded files or other LFI to RCE techniques.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"572a085c11e81a6c0dc17dc3b157f5ff45d16dcd23079195d3a663669aa03cb6","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 4.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24255","name":"CVE-2021-24255","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24255","description":"[en] The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, both via a similar method.","date":"2021-05-05"},{"id":"a6817b05241f70fdd130e386eb7cb82acd495721","name":"Essential Addons for Elementor Lite <= 4.5.3 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-lite-453-cross-site-scripting","description":"The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, both via a similar method.","date":"2021-04-13"},{"id":"7fb708da-e8c4-4455-b4f9-c4ad72f877da","name":"Essential Addons for Elementor &lt; 4.5.4 - Contributor+ Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/7fb708da-e8c4-4455-b4f9-c4ad72f877da","description":"The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, both via a similar method.\r\n\r\nThe &ldquo;Progress Bar&rdquo; widget accepts a &ldquo;progress_bar_title_html_tag&rdquo; parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a &lsquo;save_builder&rsquo; request containing JavaScript in the &ldquo;progress_bar_title_html_tag&rdquo; parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.\r\n\r\nThe &ldquo;Woo Product Compare&rdquo; widget accepts a &ldquo;table_title_tag&rdquo; parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a &lsquo;save_builder&rsquo; request containing JavaScript in the &ldquo;table_title_tag&rdquo; parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.\r\n\r\nAdditionally, the following widgets also allow JavaScript to be inserted via the following parameters: \r\nadvanced accordion:eael_adv_accordion_title_tag\r\nCreative button:creative_button_text \r\nDual Color Header: title_tag, eael_dch_subtext\r\nFancy text: eael_fancy_text_color_selector\r\nFilterable Gallery: eael_fg_all_label_text, title_tag\r\nFlipbox: eael_flipbox_front_title_tag\r\n\r\nThese vulnerabilities are nearly identical to the vulnerabilities we have recently disclosed in the main Elementor plugin: https:\/\/www.wordfence.com\/blog\/2021\/03\/cross-site-scripting-vulnerabilities-in-elementor-impact-over-7-million-sites\/","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"6d5523c3ca21eb859d265ee702f1a89c803cf3ba95afb1eb6b3783d7ed9a053c","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 4.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"eb738254130d98507e7b1e58dc9672085731b8d6","name":"WordPress Essential Addons for Elementor plugin <= 4.5.3 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-4-5-3-multiple-authenticated-stored-cross-site-scripting-xss-vulnerabilities","description":"Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress Essential Addons for Elementor plugin (versions <= 4.5.3).","date":"2021-04-13"}],"impact":[]},{"uuid":"71cfeb22a382e53f2a870c45776e398bdee231c3cf807d674f0b6d91ec635050","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 4.6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"710cc76ba88952ffa720441781c356d5dea6dee6","name":"Essential Addons for Elementor <= 4.6.4 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-464-missing-authorization","description":"The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized actions such as changing settings and installing arbitrary plugins.","date":"2021-05-05"},{"id":"CVE-2021-4446","name":"CVE-2021-4446","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-4446","description":"[en] The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized actions such as changing settings and installing arbitrary plugins.","date":"2024-10-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"30df76c511ee52e57abe57c6d223f261d1c3155ede6e5b1539aafc486d3c4517","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 4.6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b37743ae5702a88673b24a5849854f7da76a20d8","name":"Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-464-authenticated-contributor-privilege-escalation","description":"The Essential Addons for Elementor  plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Elementor page builder to create a new registration form that defaults to the user role being set to administrator and subsequently register as an administrative user.","date":"2021-05-05"},{"id":"CVE-2021-4447","name":"CVE-2021-4447","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-4447","description":"[en] The Essential Addons for Elementor  plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Elementor page builder to create a new registration form that defaults to the user role being set to administrator and subsequently register as an administrative user.","date":"2024-10-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"8847ac2441ed9b568feec3a1b7b3d055a59c96b12b64b5dbd194828f13152b12","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.7.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.7.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-32243","name":"CVE-2023-32243","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-32243","description":"[en] Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.\u00a0This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.","date":"2023-05-12"},{"id":"f0963d9d3f2351c357c129eab1809666c32898bc","name":"Essential Addons for Elementor <= 5.7.1 - Unauthenticated Arbitrary Password Reset to Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-571-unauthenticated-arbitrary-password-reset-to-privilege-escalation","description":"The Essential Addons for Elementor plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Privilege Escalation in versions up to, and including, 5.7.1. This is due to a lack of validation of a password reset key in the reset_password function. This makes it possible for unauthenticated attackers to reset the password of any user on a vulnerable site, including an administrator, if they have the email or username of the targeted account.","date":"2023-05-11"},{"id":"505dbd4722245e96d57e97b14c7e1db1e01d12a0","name":"WordPress  Essential Addons for Elementor Plugin  5.4.0-5.7.1 is vulnerable to Privilege Escalation","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-4-0-5-7-1-unauthenticated-privilege-escalation-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.7.2).\nRafie Muhammad (Patchstack) discovered and reported this Privilege Escalation vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website if high privileges are gained. This vulnerability has been fixed in version 5.7.2.","date":"2023-05-11"},{"id":"4855dbf0-d40c-46be-840b-aed1168e2191","name":"Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation","link":"https:\/\/wpscan.com\/vulnerability\/4855dbf0-d40c-46be-840b-aed1168e2191","description":"The plugin does not validate the password reset key, which could allow unauthenticated attackers to reset arbitrary account&#039;s password to anything they want, by knowing the related email or username, gaining access to them","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"e38ceff91e0c16a3412049ee20b79d1f24f7669b622d23588d92ece12bf3fb39","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-3779","name":"CVE-2023-3779","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-3779","description":"[en] The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp API key. We recommend resetting any MailChimp API keys if running a vulnerable version of this plugin with the MailChimp block enabled as the API key may have been compromised. This only affects sites running the premium version of the plugin and that have the Mailchimp block enabled on a page.","date":"2023-07-20"},{"id":"f1c9340e47854c9163ce3f1a5d802830749c9cd1","name":"Essential Addons For Elementor <=5.8.1 - Unauthenticated MailChimp API Key Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-581-unauthenticated-mailchimp-api-key-disclosure","description":"The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp API key. We recommend resetting any MailChimp API keys if running a vulnerable version of this plugin with the MailChimp block enabled as the API key may have been compromised. This only affects sites running the premium version of the plugin and that have the Mailchimp block enabled on a page.","date":"2023-07-19"},{"id":"dc3313e56030bb70577f0b3cbaefbd6f62116f9b","name":"WordPress  Essential Addons for Elementor Plugin  <= 5.8.1 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-8-1-unauthenticated-mailchimp-api-key-disclosure-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.8.2).\nUlyses Saicha discovered and reported this Sensitive Data Exposure vulnerability in WordPress Essential Addons for Elementor Plugin.  This vulnerability has been fixed in version 5.8.2.","date":"2023-07-20"},{"id":"c9c7e716-49c2-4b07-8c1c-9bf366573dff","name":"Essential Addons For Elementor &lt; 5.8.2 - Unauthenticated MailChimp API Key Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/c9c7e716-49c2-4b07-8c1c-9bf366573dff","description":"The plugin discloses the MailChimp API key in pages with the MailChimp block, allowing unauthenticated users to obtain such key","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"077aeed94bd9694d3aa080aef7419200de5e8d2f06d1cac0c1db7f438ae29f49","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.8.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.8.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"62c3f60ffdae090aac89dd40aaddec7e179c00a6","name":"Essential Addons for Elementor <= 5.8.8 - Authenticated (Contributor+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-588-authenticated-contributor-privilege-escalation","description":"The Essential Addons for Elementor  plugin for WordPress is vulnerable to privilege escalation in versions up to and including 5.8.8 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Elementor page builder to create a new registration form that defaults to the user role being set to administrator and subsequently register as an administrative user. Note that this is difficult to exploit without publishing capabilities and appears to be a regression, as an identical issue was patched in version 4.6.5.","date":"2023-09-14"},{"id":"CVE-2023-41955","name":"CVE-2023-41955","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-41955","description":"[en] Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n\/a through 5.8.8.","date":"2024-05-17"},{"id":"ab658967a655cdb0b958becb5c5e119ce898915f","name":"WordPress  Essential Addons for Elementor Plugin  <= 5.8.8 is vulnerable to Privilege Escalation","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-8-8-contributor-privilege-escalation-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.8.9).\nRafie Muhammad (Patchstack) discovered and reported this Privilege Escalation vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website if high privileges are gained. This vulnerability has been fixed in version 5.8.9.","date":"2023-09-15"},{"id":"76800214-71ac-4547-9bce-4726c51f6462","name":"Essential Addons for Elementor &lt; 5.8.9 - Authenticated (Contributor+) Privilege Escalation","link":"https:\/\/wpscan.com\/vulnerability\/76800214-71ac-4547-9bce-4726c51f6462","description":"The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 5.8.8 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Elementor page builder to create a new registration form that defaults to the user role being set to administrator and subsequently register as an administrative user. Note that this is difficult to exploit without publishing capabilities and appears to be a regression, as an identical issue was patched in version 4.6.5.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"df51397b2a8576dd5cd342264c9399f902179de451879c7945d37a6b78bba13d","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-7044","name":"CVE-2023-7044","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-7044","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ID in all versions up to, and including, 5.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access and higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-01-04"},{"id":"64beb1778782dbb48f031f2a951584a104a87a21","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-592-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ID in all versions up to, and including, 5.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access and higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-01-03"},{"id":"6bf0fdbc100936428120184c5d9e9c11fc552690","name":"WordPress  Essential Addons for Elementor Plugin  <= 5.9.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-2-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.9.3).\nWebbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.9.3.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-04"},{"id":"10a73fea-68b4-4861-8ac1-b5ac278fed11","name":"Essential Addons for Elementor &lt; 5.9.3 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/10a73fea-68b4-4861-8ac1-b5ac278fed11","description":"The Essential Addons for Elementor &ndash; Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ID in all versions up to, and including, 5.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access and higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4fc4267b80decf57c882f3ffbcb4e051066db6dcefe22c5ca06e1ff5ee5ea042","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-0586","name":"CVE-2024-0586","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-0586","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Login\/Register Element in all versions up to, and including, 5.9.4 due to insufficient input sanitization and output escaping on the custom login URL. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-05"},{"id":"33b8b1cbd24d7d1ab11598616ffb4a14027d750b","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scritping","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-594-authenticated-contributor-stored-cross-site-scritping","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Login\/Register Element in all versions up to, and including, 5.9.4 due to insufficient input sanitization and output escaping on the custom login URL. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-01-17"},{"id":"8de45ee090e9f8580b20c423c80539493a995a8a","name":"WordPress  Essential Addons for Elementor Plugin  <= 5.9.4 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-4-authenticated-contributor-stored-cross-site-scritping-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.9.5).\nWebbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.9.5.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-18"},{"id":"427af876-f60c-4219-b5de-1c72b41c0136","name":"Essential Addons for Elementor &lt; 5.9.5 - Contributor+ Stored Cross-Site Scritping","link":"https:\/\/wpscan.com\/vulnerability\/427af876-f60c-4219-b5de-1c72b41c0136","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the Login\/Register Element in all versions up to, and including, 5.9.4 due to insufficient input sanitization and output escaping on the custom login URL. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"18721d8bb1352060c36744b84438e1999500387259dcf809625d897283da7d11","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-0585","name":"CVE-2024-0585","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-0585","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 5.9.4 due to insufficient input sanitization and output escaping on the Image URL. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-05"},{"id":"e3132470d0facc39f05a09b04589aa547c80d141","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-594-authenticated-contributor-stored-cross-site-scripting-via-image-url","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 5.9.4 due to insufficient input sanitization and output escaping on the Image URL. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-01-17"},{"id":"cb20fa9f58b6ebd943750d030945300e2b417982","name":"WordPress  Essential Addons for Elementor Plugin  <= 5.9.4 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-4-authenticated-contributor-stored-cross-site-scripting-via-image-url-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.9.5).\nWebbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.9.5.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-18"},{"id":"6955630f-29c0-4996-9184-325ea153dfcf","name":"Essential Addons for Elementor &lt; 5.9.5 - Contributor+ Stored Cross-Site Scripting via Image URl","link":"https:\/\/wpscan.com\/vulnerability\/6955630f-29c0-4996-9184-325ea153dfcf","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s Filterable Gallery widget in all versions up to, and including, 5.9.4 due to insufficient input sanitization and output escaping on the Image URL. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f5036fdb4c35a5b1d47ababcb4329aeee01a986c5a0ddd3b6a725f24c225ef3d","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-0954","name":"CVE-2024-0954","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-0954","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting through editing context via the 'data-eael-wrapper-link' wrapper in all versions up to, and including, 5.9.7 due to insufficient input sanitization and output escaping on user supplied protocols. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-05"},{"id":"d483aa75ef3c4377840bd38a51359f1a61d945c1","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-597-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting through editing context via the 'data-eael-wrapper-link' wrapper in all versions up to, and including, 5.9.7 due to insufficient input sanitization and output escaping on user supplied protocols. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-01"},{"id":"f3da83a34eef6e017fc07f0195843f36db68ac60","name":"WordPress  Essential Addons for Elementor Plugin  <= 5.9.7 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-7-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.9.8).\nWebbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.9.8.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"d6f1740c-9e31-4be1-81ff-62bfd5b568fe","name":"Essential Addons for Elementor &lt; 5.9.8 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/d6f1740c-9e31-4be1-81ff-62bfd5b568fe","description":"The plugin is vulnerable to Stored Cross-Site Scripting through editing context via the &#039;data-eael-wrapper-link&#039; wrapper due to insufficient input sanitization and output escaping on user supplied protocols, allowing authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7565a4425505d304d5cc97b2001df0c1b90080e507fab9021fe328eac6d836af","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1171","name":"CVE-2024-1171","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1171","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery Widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-20"},{"id":"9759cd6bebc30eb42ab782f17d57f854fdaf8ad7","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-598-authenticated-contributor-stored-cross-site-scripting-via-filterable-gallery","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery Widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-12"},{"id":"800db312b3d1979d9f68b73bed7415cbd519b4eb","name":"WordPress  Essential Addons for Elementor Plugin  <= 5.9.8 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-8-authenticated-contributor-stored-cross-site-scripting-via-filterable-gallery-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.9.9).\nMdr discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.9.9.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"49240593-fb6a-4d8c-a369-c4606cd9ee24","name":"Essential Addons for Elementor &ndash; Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders &lt; 5.9.9 - Contributor+ Stored Cross-Site Scripting via Filterable Gallery","link":"https:\/\/wpscan.com\/vulnerability\/49240593-fb6a-4d8c-a369-c4606cd9ee24","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s Filterable Gallery Widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"545ffdea2a7822410080a3f3d46b7d8c593da00a7fa647b1b8f2b39c5fa8ecfd","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1236","name":"CVE-2024-1236","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1236","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Filterable Controls label icon parameter in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-20"},{"id":"e2e3b5263b50519a11e5742ce8788510837aa22a","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-598-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Filterable Controls label icon parameter in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-12"},{"id":"0349e3ab07e0a420f0d9951ed30d73e3e8713b42","name":"WordPress  Essential Addons for Elementor Plugin  <= 5.9.8 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-8-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.9.9).\nWebbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.9.9.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"5e0c33f9-178d-42ca-bc5f-f1354be951e5","name":"Essential Addons for Elementor &ndash; Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders &lt; 5.9.9 - Contributor+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/5e0c33f9-178d-42ca-bc5f-f1354be951e5","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the Filterable Controls label icon parameter in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8f37472c9af41690870f9aeb9504c274c94285a24807cd856ae27619e0d0ee1d","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1276","name":"CVE-2024-1276","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1276","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Content Ticker arrow attribute in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-20"},{"id":"1ed35f41260dd5dc4f8091e8ca45ae7e8acb8434","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-598-authenticated-contributor-stored-cross-site-scripting-1","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Content Ticker arrow attribute in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-12"},{"id":"5ab537c4d26f332312c3f1582e91f63aa59876b6","name":"WordPress  Essential Addons for Elementor Plugin  <= 5.9.8 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-8-authenticated-contributor-stored-cross-site-scripting-vulnerability-2","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.9.9).\nRandomRoot discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.9.9.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"538a02f8-1aac-4f5e-ad22-7b98745be27e","name":"Essential Addons for Elementor &ndash; Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders &lt; 5.9.9 - Contributor+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/538a02f8-1aac-4f5e-ad22-7b98745be27e","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the Content Ticker arrow attribute in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"26a806c469408947a4e784cbfb34bb419d7436c5defea4341a7cae79d6b7fdd1","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1172","name":"CVE-2024-1172","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1172","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-20"},{"id":"bdb3af5b127835c25b650de15a306dea2be354eb","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-598-authenticated-contributor-stored-cross-site-scripting-via-accordion","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-12"},{"id":"57f10fbdfba67a032dc8667d246b386e20fb1d07","name":"WordPress  Essential Addons for Elementor Plugin  <= 5.9.8 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-8-authenticated-contributor-stored-cross-site-scripting-via-accordion-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.9.9).\nwesley (wcraft) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.9.9.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"0a8dde9a-bac0-498d-a68e-466a29401a08","name":"Essential Addons for Elementor &ndash; Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders &lt; 5.9.9 - Contributor+ Stored Cross-Site Scripting via Accordion","link":"https:\/\/wpscan.com\/vulnerability\/0a8dde9a-bac0-498d-a68e-466a29401a08","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s Accordion widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e99f22ecb84db6a391630fc730eb92720bba7af93f2334704a8549e86986fbfc","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1537","name":"CVE-2024-1537","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1537","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Data Table widget in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-13"},{"id":"3bb67910c07deeef3898ea8662a9aca287052298","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-599-authenticated-contributor-stored-cross-site-scripting-via-data-table","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Data Table widget in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-11"},{"id":"4153e07cf5805e23524dc1112c97747aa3b4cf54","name":"WordPress  Essential Addons for Elementor Plugin    <= 5.9.9 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-plugin-5-9-9-authenticated-contributor-stored-cross-site-scripting-via-data-table-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.9.10).\nwesley (wcraft) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.9.10.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"76499eab-5dee-4f9a-b7cf-d89d46ce5e8b","name":"Essential Addons for Elementor &lt; 5.9.10 - Contributor+ Stored Cross-Site Scripting via Data Table","link":"https:\/\/wpscan.com\/vulnerability\/76499eab-5dee-4f9a-b7cf-d89d46ce5e8b","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s Data Table widget in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"17fd38e800424fdcd6fbcf8f48524e19656bb7d9933d175432e31e3b5e7701ea","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1536","name":"CVE-2024-1536","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1536","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's event calendar widget in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-13"},{"id":"2062918209be87e460c4cf15a2b7d93fe9a58962","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-599-authenticated-contributor-stored-cross-site-scripting-via-event-calendar","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's event calendar widget in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-11"},{"id":"0b79529c6107c36f66c074185f9328b9f8697e27","name":"WordPress  Essential Addons for Elementor Plugin    <= 5.9.9 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-plugin-5-9-9-authenticated-contributor-stored-cross-site-scripting-via-event-calendar-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.9.10).\nWebbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.9.10.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"fc358e07-84d1-48c2-bc0a-72c399b3163c","name":"Essential Addons for Elementor &lt; 5.9.10 - Contributor+ Stored Cross-Site Scripting via Event Calendar","link":"https:\/\/wpscan.com\/vulnerability\/fc358e07-84d1-48c2-bc0a-72c399b3163c","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s event calendar widget in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"l","score":"7.4","severity":"h","exploitable":"3.1","impact":"3.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:L","score":"7.4","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"low","exploitable":"3.1","impact":"3.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2a9d32c609d5d98da1e27cfd4b3bfc69c224146ef68bbee46ae709c97102017c","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.12","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.12","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2623","name":"CVE-2024-2623","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2623","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's message parameter in all versions up to, and including, 5.9.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-09"},{"id":"93d927dd974eaf807c0e116648d0c06261098fb7","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-5911-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's message parameter in all versions up to, and including, 5.9.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-25"},{"id":"92f02b4a2cef7b4a3963e4ff6421f08ee98c3d74","name":"WordPress  Essential Addons for Elementor Plugin    <= 5.9.11 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-11-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.9.12).\nWebbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.9.12.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"78d2f15c-a336-4749-bd1e-9507165061f3","name":"Essential Addons for Elementor &lt; 5.9.12 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/78d2f15c-a336-4749-bd1e-9507165061f3","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the countdown widget&#039;s message parameter due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"350d9a00382ed0831cc8f3bdc269985405f655d0d942c27968acb0bf95d940f3","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.12","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.12","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2650","name":"CVE-2024-2650","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2650","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the alignment parameter in the Woo Product Carousel widget in all versions up to, and including, 5.9.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-09"},{"id":"379f5f74a63b3d0fff79bd9e4f20bfbd1854b65d","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-5911-authenticated-contributor-stored-cross-site-scripting-1","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the alignment parameter in the Woo Product Carousel widget in all versions up to, and including, 5.9.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-25"},{"id":"8a3c90da-f467-4795-b912-afe7c43e8258","name":"Essential Addons for Elementor &lt; 5.9.12 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/8a3c90da-f467-4795-b912-afe7c43e8258","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the alignment parameter in the Woo Product Carousel widget due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-20","name":"Improper Input Validation","description":"The product receives input or data, but it does\n        not validate or incorrectly validates that the input has the\n        properties that are required to process the data safely and\n        correctly."},{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8ced72bdab0c1cba3662b1c779582c27052b709040687f724125a7ef0d1498c6","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3018","name":"CVE-2024-3018","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3018","description":"[en] The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the \"Login | Register Form\" widget (disabled by default). This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2024-03-30"},{"id":"4de7f6203bec2141b6c9c34056a28ee22d6b3349","name":"Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpassword","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-5913-authenticated-author-php-object-injection-via-error-resetpassword","description":"The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the \"Login | Register Form\" widget (disabled by default). This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2024-03-29"},{"id":"5af23e99311775e9c3e30b1607a19d98094ecea2","name":"WordPress  Essential Addons for Elementor Plugin    <= 5.9.13 is vulnerable to PHP Object Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-13-authenticated-author-php-object-injection-via-error-resetpassword-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.9.14).\nNg\u00f4 Thi\u00ean An (ancorn_) discovered and reported this PHP Object Injection vulnerability in WordPress Essential Addons for Elementor Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more if a proper POP chain is present. This vulnerability has been fixed in version 5.9.14.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"1f720bb4-0018-4d46-83bb-034cb4d5c372","name":"Essential Addons for Elementor &lt; 5.9.14 - Author+ PHP Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/1f720bb4-0018-4d46-83bb-034cb4d5c372","description":"The plugin is vulnerable to PHP Object Injection via deserialization of untrusted input from the &#039;error_resetpassword&#039; attribute of the &quot;Login | Register Form&quot; widget (disabled by default). This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"7ae3290dfae6f9defd4440b58685eb1edd73bb7ef50a568bfb791641b85c2512","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2974","name":"CVE-2024-2974","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2974","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated attackers to extract sensitive data including private and draft posts.","date":"2024-04-09"},{"id":"e88a8fae9ab81efa4f64abf934c4b7822611d3e8","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-5913-unauthenticated-sensitive-information-exposure","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated attackers to extract sensitive data including private and draft posts.","date":"2024-03-29"},{"id":"40e60905f2a461f149f898c8072180ba78f51832","name":"WordPress  Essential Addons for Elementor Plugin    <= 5.9.13 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-13-unauthenticated-sensitive-information-exposure-vulnerability","description":"Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 5.9.14).\nAnkit Patel discovered and reported this Sensitive Data Exposure vulnerability in WordPress Essential Addons for Elementor Plugin.  This vulnerability has been fixed in version 5.9.14.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"e2aa7fa0-d9c4-4a41-9479-350ea2ba375a","name":"Essential Addons for Elementor &lt; 5.9.14 - Unauthenticated Private\/Draft Posts Access","link":"https:\/\/wpscan.com\/vulnerability\/e2aa7fa0-d9c4-4a41-9479-350ea2ba375a","description":"The plugin is vulnerable to Sensitive Information Exposure via the load_more function. This can allow unauthenticated attackers to extract sensitive data including private and draft posts.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."},{"cwe":"CWE-922","name":"Insecure Storage of Sensitive Information","description":"The product stores sensitive information without properly limiting read or write access by unauthorized actors."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4ac269a969609c3bcbeb1752b968b027078a336df606a49732e7c651a70a66fb","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3333","name":"CVE-2024-3333","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3333","description":"[en] The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attributes of widgets in all versions up to, and including, 5.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-17"},{"id":"9520042502d0b2223385c6abdb242202da5c33e2","name":"Essential Addons for Elementor <= 5.9.14 - Authenticated (Contributor+) Store Cross-Site Scripting via Widget URL Attribute","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-5914-authenticated-contributor-store-cross-site-scripting-via-widget-url-attribute","description":"The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attributes of widgets in all versions up to, and including, 5.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-16"},{"id":"73c538b062e178ff72b2d86de1aadc32fa5aba28","name":"WordPress Essential Addons for Elementor Plugin <= 5.9.14 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-14-authenticated-contributor-store-cross-site-scripting-via-widget-url-attribute-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 5.9.14 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 5.9.14<\/p><p>Fixed in version 5.9.15 <\/p>","date":"2024-04-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"cad28b177666f3bc6dbdb61e2e87ffc136753d3b660d8112fa9af4d67ac7c093","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3733","name":"CVE-2024-3733","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3733","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery() functions. This makes it possible for unauthenticated attackers to extract posts that may be in private or draft status.","date":"2024-04-25"},{"id":"b62d516925570cc13c0230197aeb3e5b64cda1bb","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-5915-information-exposure","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery() functions. This makes it possible for unauthenticated attackers to extract posts that may be in private or draft status.","date":"2024-04-24"},{"id":"920569f3417662f242e725d7b9a94ed779f46336","name":"WordPress Essential Addons for Elementor Plugin <= 5.9.15 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-15-information-exposure-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 5.9.15 is vulnerable to Sensitive Data Exposure<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 5.9.15<\/p><p>Fixed in version 5.9.16 <\/p>","date":"2024-04-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."},{"cwe":"CWE-922","name":"Insecure Storage of Sensitive Information","description":"The product stores sensitive information without properly limiting read or write access by unauthorized actors."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c637d6df7dbd47a1d8980771ae656d30adc04894d41ec809978ac33aefae2b1f","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3728","name":"CVE-2024-3728","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3728","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery & Interactive Circle widgets in all versions up to, and including, 5.9.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-02"},{"id":"f72d779873fdbeb99a8a7fb4d89e2f4a99e5ccba","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-5915-authenticated-contributor-stored-cross-site-scripting-via-filterable-gallery-interactive-circle","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery & Interactive Circle widgets in all versions up to, and including, 5.9.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8ff9ff76012569042686abbe102b8bd3536839ebb0e19c5ca6fcd035cff37a66","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4003","name":"CVE-2024-4003","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4003","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_team_members_image_rounded parameter in the Team Members widget in all versions up to, and including, 5.9.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-02"},{"id":"13b57b31675bed157c1e1fcac0f5c3cfd318ae37","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-5915-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_team_members_image_rounded parameter in the Team Members widget in all versions up to, and including, 5.9.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-20","name":"Improper Input Validation","description":"The product receives input or data, but it does\n        not validate or incorrectly validates that the input has the\n        properties that are required to process the data safely and\n        correctly."},{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"eaa4968e59e133598374089588e5e467653a080a2fa2a304c9c0ab1a0ccf74c0","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.18","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.18","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4156","name":"CVE-2024-4156","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4156","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018eael_event_text_color\u2019 parameter in versions up to, and including, 5.9.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-02"},{"id":"f7644b70d3e89d23a6e8d7c7524e62502be0adc9","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-5917-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018eael_event_text_color\u2019 parameter in versions up to, and including, 5.9.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-30"},{"id":"d5ca0ee4f3e5f4a1e8238d77b150711b37ae3760","name":"WordPress Essential Addons for Elementor Plugin <= 5.9.17 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-17-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 5.9.17 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 5.9.17<\/p><p>Fixed in version 5.9.18 <\/p>","date":"2024-05-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f9e82d8fc0202876e46a190ea18360bbde8296fb6a5f3e0be7f474095fa8765c","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.20","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.20","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4448","name":"CVE-2024-4448","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4448","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table' widgets in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-10"},{"id":"fab6c4701a35dae2c14d8f13d6ae0a56ff1f5076","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-5919-authenticated-contributor-stored-cross-site-scripting-via-dual-color-header-event-calendar-advanced-data-table","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table' widgets in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"001219a209e125db41ba3e4bd8c1b0dec71e7faf6ad98fc8ef0e43c21bde461d","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.20","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.20","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4275","name":"CVE-2024-4275","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4275","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Interactive Circle widget in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-10"},{"id":"856e06feda738e3e87ba5e37b5807fc371969777","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Interactive Circles'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-5919-authenticated-contributor-stored-cross-site-scripting-via-interactive-circles","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Interactive Circle widget in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-09"},{"id":"f69d1828dfd6a2925310c3e72ac1ed16d5e97434","name":"WordPress Essential Addons for Elementor Plugin <= 5.9.19 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-19-authenticated-contributor-stored-cross-site-scripting-via-interactive-circles-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 5.9.19 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 5.9.19<\/p><p>Fixed in version 5.9.20 <\/p>","date":"2024-05-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e5a43e792762f660a530cee7f714e3b2aa7e8d1560e9fe181d2bbf8a1ae5adea","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.20","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.20","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4449","name":"CVE-2024-4449","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4449","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Fancy Text', 'Filter Gallery', 'Sticky Video', 'Content Ticker', 'Woo Product Gallery', & 'Twitter Feed' widgets in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-10"},{"id":"e49489afd0bbeff460cfa5ad6e6bd3d3f4f3b91d","name":"Essential Addons for Elementor  <= 5.9.19 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Several Widgets","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-5919-authenticated-contributor-dom-based-stored-cross-site-scripting-via-several-widgets","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Fancy Text', 'Filter Gallery', 'Sticky Video', 'Content Ticker', 'Woo Product Gallery', & 'Twitter Feed' widgets in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3c06e740ae6703f0cee2d85bd0765891de49574bf20096950c926ab0bb20935a","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4624","name":"CVE-2024-4624","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4624","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018eael_ext_toc_title_tag\u2019 parameter in versions up to, and including, 5.9.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-14"},{"id":"24f6b94deaa12a3e2ffcf8e9231af60371486bb1","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.20 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-5920-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018eael_ext_toc_title_tag\u2019 parameter in versions up to, and including, 5.9.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-13"},{"id":"2e29323a15c66223d8adf8ac4b77aa25247642f5","name":"WordPress Essential Addons for Elementor Plugin <= 5.9.20 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-20-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 5.9.20 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 5.9.20<\/p><p>Fixed in version 5.9.21 <\/p>","date":"2024-05-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"fddadedb6fac691bb7086fe70ff11ba33ed1ac1f9c3b79820325dd630bd261e0","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-34764","name":"CVE-2024-34764","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-34764","description":"","date":"2024-06-03"},{"id":"e0cd435e05d2d26ef59f8e4805fb1f305cdeaa1c","name":"WordPress Essential Addons for Elementor Plugin <= 5.9.15 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-15-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 5.9.15 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 5.9.15<\/p><p>Fixed in version 5.9.16 <\/p>","date":"2024-05-17"},{"id":"6780944302eeeada77d62decc45c167f4671e3a0","name":"Essential Addons for Elementor <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-5915-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-17"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"1aa2ff8f9752f29e0eb1e2ebdaa6c0592602d0202fb45233bc376803a913e4a7","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5073","name":"CVE-2024-5073","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5073","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Feed component in all versions up to, and including, 5.9.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-30"},{"id":"a97ffea03bc1af9eab7d2f890c0fcb4a09de4700","name":"Essential Addons for Elementor <= 5.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Feed","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-5921-authenticated-contributor-stored-cross-site-scripting-via-twitter-feed","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Feed component in all versions up to, and including, 5.9.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-29"},{"id":"6ba61b0cfb454c6d9614da707c58d92d47dd9adc","name":"WordPress Essential Addons for Elementor Plugin <= 5.9.21 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-21-authenticated-contributor-stored-cross-site-scripting-via-twitter-feed-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 5.9.21 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 5.9.21<\/p><p>Fixed in version 5.9.22 <\/p>","date":"2024-05-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4ae39071c1e5583b3228cda6cb511a3bd229678826c4510ea83a0c32e69af84a","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.23","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.23","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5188","name":"CVE-2024-5188","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5188","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_manual_calendar_events' function in all versions up to, and including, 5.9.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-06"},{"id":"43de40297178b933fd1cf21fabb6e4adc1c8234d","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.22 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-5922-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_manual_calendar_events' function in all versions up to, and including, 5.9.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-05"},{"id":"12ae93daa1c21183ba6fd81aab7ba2a6853b8783","name":"WordPress Essential Addons for Elementor Plugin <= 5.9.22 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-22-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 5.9.22 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 5.9.22<\/p><p>Fixed in version 5.9.23 <\/p>","date":"2024-06-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ebd9f73c8d50b7db4e3b77b07ae5b7d83b9b88884b720e151156e996eccea93c","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.24","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.24","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5189","name":"CVE-2024-5189","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5189","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018custom_js\u2019 parameter in all versions up to, and including, 5.9.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-11"},{"id":"b2af104380dbe9918a181ff86d3d96fe45bc379e","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.23 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-5923-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018custom_js\u2019 parameter in all versions up to, and including, 5.9.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-10"},{"id":"e3311b83af45d138ca20bdc01c1cd80669d5e927","name":"WordPress Essential Addons for Elementor Plugin <= 5.9.23 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-23-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 5.9.23 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 5.9.23<\/p><p>Fixed in version 5.9.24 <\/p>","date":"2024-06-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7e4961f092cbe1290b4c19ad73c4df23f8afa178af089457a6370b5b3dd66e07","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 5.9.27","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.9.27","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-39649","name":"CVE-2024-39649","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-39649","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite.This issue affects Essential Addons for Elementor: from n\/a through <= 5.9.26.","date":"2024-08-01"},{"id":"c058e9bc345c12b7970a5d12ef1116b39fd8bcca","name":"WordPress Essential Addons for Elementor Plugin <= 5.9.26 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-26-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 5.9.26 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 5.9.26<\/p><p>Fixed in version 5.9.27 <\/p>","date":"2024-08-01"},{"id":"897e8b5a01d5d693f504c12302d10c99a6e3bbfe","name":"Essential Addons for Elementor <= 5.9.26 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-5926-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-08-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"32cc22ed3b34d6a8650bc28470ad0efba1c7e9ca9632b06d9555096126ffc867","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-7092","name":"CVE-2024-7092","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-7092","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018no_more_items_text\u2019 parameter in all versions up to, and including, 5.9.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-08-13"},{"id":"50fae011b7c68fbb12921dadbf163635ebb0083a","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via no_more_items_text Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-5927-authenticated-contributor-stored-cross-site-scripting-via-no-more-items-text-parameter","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018no_more_items_text\u2019 parameter in all versions up to, and including, 5.9.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-08-12"},{"id":"95e5d3613cc31b950c60cd9f2524d2bd7de08f0d","name":"WordPress Essential Addons for Elementor Plugin <= 5.9.27 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-5-9-27-authenticated-contributor-stored-cross-site-scripting-via-no-more-items-text-parameter-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 5.9.27 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 5.9.27<\/p><p>Fixed in version 6.0.0 <\/p>","date":"2024-08-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e759e85e4df0ce0207c78216321777bb3d5e747f05790656689dabf09c792eb0","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8440","name":"CVE-2024-8440","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8440","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-09-11"},{"id":"bf41a19ad5cc9c124d1f1cc538292105623f2e95","name":"Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-603-authenticated-contributor-stored-cross-site-scripting-via-fancy-text-widget","description":"The Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-09-10"},{"id":"60ccf1bdaea54ec97cab2aaf10c171c016441dd5","name":"WordPress Essential Addons for Elementor Plugin <= 6.0.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-6-0-3-authenticated-contributor-stored-cross-site-scripting-via-fancy-text-widget-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 6.0.3 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 6.0.3<\/p><p>Fixed in version 6.0.4 <\/p>","date":"2024-09-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f729f892d48b54e02f2c564bd711375bb1e923caba13b6fab151cc567b3aaf77","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8742","name":"CVE-2024-8742","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8742","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-09-13"},{"id":"4f610deae52c2c0efa21704b45ed142656b40d80","name":"Essential Addons for Elementor <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-603-authenticated-contributor-stored-cross-site-scripting-via-filterable-gallery-widget","description":"The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-09-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6ffabbe49bb2555c7dd82906565a898c8f3239196350168c5ad3f0ac40a12311","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.0.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.0.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8979","name":"CVE-2024-8979","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8979","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_lostpassword_user_email_controls' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including usernames and passwords of any user, including Administrators, as long as that user opens the email notification for a password change request and images are not blocked by the email client.","date":"2024-11-15"},{"id":"bf734ff965b005b31844ab7eddd7dde1585679ac","name":"WordPress Essential Addons for Elementor Plugin <= 6.0.9 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-6-0-9-authenticated-author-sensitive-information-exposure-to-privilege-escalation-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 6.0.9 is vulnerable to Sensitive Data Exposure<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 6.0.9<\/p><p>Fixed in version 6.0.10 <\/p>","date":"2024-11-14"},{"id":"a2497deb277a256b3c32ee50baaab9a12bfad0be","name":"Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-addon-templates-widgets-kits-woocommerce-builders-609-authenticated-author-sensitive-information-exposure-to-privilege-escalation","description":"The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_lostpassword_user_email_controls' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including usernames and passwords of any user, including Administrators, as long as that user opens the email notification for a password change request and images are not blocked by the email client.","date":"2024-11-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"u","c":"h","i":"n","a":"n","score":"5.7","severity":"m","exploitable":"2.1","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:U\/C:H\/I:N\/A:N","score":"5.7","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.1","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"e7d4c94b102da37a7550f4570ae28a73c614b5da14964f5913ae718cb8c5fe9e","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.0.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.0.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8961","name":"CVE-2024-8961","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8961","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018nomore_items_text\u2019 parameter in all versions up to, and including, 6.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-11-15"},{"id":"1c86fdce6487baf1cbfed5b811564b1eeaffa2f9","name":"WordPress Essential Addons for Elementor Plugin <= 6.0.7 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-6-0-7-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 6.0.7 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 6.0.7<\/p><p>Fixed in version 6.0.8 <\/p>","date":"2024-11-14"},{"id":"75f8ba69e6ef08b72b10384e34cc156e4adcdd06","name":"Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-addon-templates-widgets-kits-woocommerce-builders-607-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018nomore_items_text\u2019 parameter in all versions up to, and including, 6.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-11-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"820821057c1070430aa254432e14666085b73bbda17033b4b082a3288c05a8dd","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.0.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.0.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8978","name":"CVE-2024-8978","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8978","description":"[en] The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_register_user_email_controls' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including usernames and passwords of any users who register via the Login | Register Form widget, as long as that user opens the email notification for successful registration.","date":"2024-11-15"},{"id":"70e3f64174e5e6db84c4e9fc14be3325fbd19a5b","name":"WordPress Essential Addons for Elementor Plugin <= 6.0.9 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-6-0-9-authenticated-contributor-sensitive-information-exposure-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 6.0.9 is vulnerable to Sensitive Data Exposure<\/p><p>Software: Essential Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/essential-addons-for-elementor-lite\/#developers<\/p><p>Affected Version <= 6.0.9<\/p><p>Fixed in version 6.0.10 <\/p>","date":"2024-11-14"},{"id":"7c8a4dc4516610b1f75b3b3163fdcdf1afc1ad60","name":"Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Contributor+) Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-addon-templates-widgets-kits-woocommerce-builders-609-authenticated-contributor-sensitive-information-exposure","description":"The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_register_user_email_controls' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including usernames and passwords of any users who register via the Login | Register Form widget, as long as that user opens the email notification for successful registration.","date":"2024-11-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"u","c":"h","i":"n","a":"n","score":"5.7","severity":"m","exploitable":"2.1","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:U\/C:H\/I:N\/A:N","score":"5.7","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.1","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"12c38c3ac8e7f41ecb3c70ec27f50ea42537b63334701e96f68b86738e07e0aa","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.0.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.0.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-56063","name":"CVE-2024-56063","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-56063","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons for Elementor: from n\/a through <= 6.0.7.","date":"2024-12-31"},{"id":"04cecd24eb4cebe5dab334846115bfdc6cd046e0","name":"WordPress Essential Addons for Elementor Plugin <= 6.0.7 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/essential-addons-for-elementor-lite\/vulnerability\/wordpress-essential-addons-for-elementor-plugin-6-0-7-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Essential Addons for Elementor Plugin <= 6.0.7 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Essential Addons for Elementor<\/p><p>Fixed in version 6.0.8 <\/p><p>Affected Version <= 6.0.7<\/p><p>CVE: CVE-2024-56063<\/p>","date":"2024-12-18"},{"id":"ac58476487ec51871d2cf9cf636fd06aeb8ad7a4","name":"Essential Addons for Elementor <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-607-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-18"},{"id":"EUVD-2024-52961","name":"EUVD-2024-52961","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-52961","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS.This issue affects Essential Addons for Elementor: from n\/a through 6.0.7.","date":"2024-12-31"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"ca3d0cfb0361a8e5f39704d94fd14b0542b13fb536048debc5ee3171748702d6","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.1.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.1.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-39589","name":"CVE-2025-39589","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-39589","description":"[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper Essential Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Essential Addons for Elementor: from n\/a through 6.1.9.","date":"2025-04-16"},{"id":"EUVD-2025-11293","name":"EUVD-2025-11293","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-11293","description":"Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper Essential Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Essential Addons for Elementor: from n\/a through 6.1.9.","date":"2025-04-16"},{"id":"e0175a5859daeadb95f247045ba1f42cabda0c4b","name":"Essential Addons for Elementor <= 6.1.9 - Authenticated (Contributor+) Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-619-authenticated-contributor-information-disclosure","description":"The Essential Addons for Elementor \u2013 Popular Elementor Addon With Ready Templates, Advanced Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.1.9. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.","date":"2025-04-16"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-497","name":"Exposure of Sensitive System Information to an Unauthorized Control Sphere","description":"The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":null,"impact":null}}},{"uuid":"6c5928d79a47329231cc933e3b336a1061eed6e703441c04102246f2b8f6a39d","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.1.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.1.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-39590","name":"CVE-2025-39590","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-39590","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS. This issue affects Essential Addons for Elementor: from n\/a through 6.1.9.","date":"2025-04-16"},{"id":"EUVD-2025-11299","name":"EUVD-2025-11299","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-11299","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS. This issue affects Essential Addons for Elementor: from n\/a through 6.1.9.","date":"2025-04-16"},{"id":"17279499010282437a594f65e542aeb88916352e","name":"Essential Addons for Elementor <= 6.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-619-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-04-16"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":null,"impact":null}}},{"uuid":"665bbec7688ad9f0b2a6971f54043b05af73a64bb9f207f7895115abe461acd6","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.0.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.0.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-24752","name":"CVE-2025-24752","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-24752","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Reflected XSS.This issue affects Essential Addons for Elementor: from n\/a through <= 6.0.14.","date":"2025-04-17"},{"id":"EUVD-2025-11615","name":"EUVD-2025-11615","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-11615","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Reflected XSS. This issue affects Essential Addons for Elementor: from n\/a through 6.0.14.","date":"2025-04-17"},{"id":"4fef7d0158cc787ec134aa1e78740d596cc15d2b","name":"Essential Addons for Elementor <= 6.0.14 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-6014-reflected-cross-site-scripting","description":"The Essential Addons for Elementor \u2013 Popular Elementor Addon With Ready Templates, Advanced Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 6.0.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2025-02-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.031"}},{"uuid":"bf0c1b86ba26df767bf64fa5982e17b0c00a50ec4586c1e401437b0c9599c846","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.1.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.1.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-9994","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-9994","description":"The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_pricing_item_tooltip_content parameter of the Pricing Table Widget in all versions up to, and including, 6.1.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"de304f6318388227bb017ab78ad33d540fe2464f","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-6112-authenticatedcontributor-stored-cross-site-scripting-via-pricing-table-widget","description":"The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_pricing_item_tooltip_content parameter of the Pricing Table Widget in all versions up to, and including, 6.1.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-06"},{"id":"EUVD-2024-54656","name":"EUVD-2024-54656","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-54656","description":"The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_pricing_item_tooltip_content parameter of the Pricing Table Widget in all versions up to, and including, 6.1.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"90891652df935e485b282b3c9a86cdd259d80b4b65fec2c57136bb9b302d983f","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.1.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.1.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-9993","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-9993","description":"The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_event_details_text parameter of Event Calendar Widget in all versions up to, and including, 6.1.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"51a8832df62f1760cad507ff090045325a8a2afd","name":"Essential Addons for Elementor \u2013 Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-best-elementor-templates-widgets-kits-woocommerce-builders-6112-authenticatedcontributor-stored-cross-site-scripting-via-event-calendar-widget","description":"The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_event_details_text parameter of Event Calendar Widget in all versions up to, and including, 6.1.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-06"},{"id":"EUVD-2024-54655","name":"EUVD-2024-54655","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-54655","description":"The Essential Addons for Elementor \u2013 Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_event_details_text parameter of Event Calendar Widget in all versions up to, and including, 6.1.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d0cb991baf73820f73071017395749ae1e42d2169cb54c8769678966cc5d5b1c","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.0.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.0.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8fdec6763b3c730130b642406e93234959989593","name":"Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/multiple-plugins-various-versions-authenticated-contributor-stored-dom-based-cross-site-scripting-via-magnific-popups-javascript-library","description":"Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.","date":"2025-07-02"},{"id":"CVE-2024-5647","name":"CVE-2024-5647","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5647","description":"[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.","date":"2025-07-03"},{"id":"c2998af6-d000-4da5-a60d-dbc6e52474bf","name":"Magnific Popups JavaScript Library &lt; 1.2.0 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/c2998af6-d000-4da5-a60d-dbc6e52474bf","description":"Multiple plugins are vulnerable to Stored Cross-Site Scripting via the plugin&#039;s bundled Magnific Popups library (version 1.1.0) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.","date":"2025-07-02"},{"id":"EUVD-2024-54725","name":"EUVD-2024-54725","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-54725","description":"Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.","date":"2025-07-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"acf3a873c27fa8db3bb408365a2ca5ac119fbe72daef124a7f285f1dd831af89","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.1.20","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.1.20","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-6244","name":"Essential Addons for Elementor \u2013 Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-6244","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"b7389b0c8a74e153982283588f4e9fdd5680a91a","name":"Essential Addons for Elementor \u2013 Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-popular-elementor-templates-and-widgets-6119-authenticated-contributor-stored-cross-site-scripting-via-calendar-and-business-reviews-widgets","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-07-07"},{"id":"EUVD-2025-20374","name":"EUVD-2025-20374","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-20374","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-07-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ecba0dab414aa015b61572d71bdae89ffa09b88a34f9a73ac8aceabeea80f760","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-8451","name":"Essential Addons for Elementor \u2013 Popular Elementor Templates and Widgets <= 6.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items'","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-8451","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the \u2018data-gallery-items\u2019 parameter in all versions up to, and including, 6.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"de0a12250d2270e0353a7d5201e27252b9875d44","name":"Essential Addons for Elementor \u2013 Popular Elementor Templates and Widgets <= 6.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-popular-elementor-templates-and-widgets-622-authenticated-contributor-dom-based-stored-cross-site-scripting-via-data-gallery-items","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the \u2018data-gallery-items\u2019 parameter in all versions up to, and including, 6.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-08-14"},{"id":"EUVD-2025-24992","name":"EUVD-2025-24992","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-24992","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the \u2018data-gallery-items\u2019 parameter in all versions up to, and including, 6.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-08-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5abd3f6862f0ddccbf9a74319c2f30bd73416150db254ea8d19c3428b6c91ed2","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.3.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.3.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-64352","name":"CVE-2025-64352","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-64352","description":"[en] Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n\/a through <= 6.2.4.","date":"2025-10-31"},{"id":"bc9b069dea347e7529a0ed8acb9848f4279095b0","name":"Essential Addons for Elementor <= 6.2.4 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-624-missing-authorization","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.2.4. This makes it possible for authenticated attackers, with Author-level access and above, to perform an unauthorized action.","date":"2025-09-17"},{"id":"EUVD-2025-37340","name":"EUVD-2025-37340","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-37340","description":"Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n\/a through <= 6.2.4.","date":"2025-10-31"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"2.7","severity":"l","exploitable":"1.2","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"2.7","severity":"low","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"1.2","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e9a4ac10ab3f4358a3c7ff6e9c667945dd8f1309917172130f817652c81c64bf","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-13977","name":"CVE-2025-13977","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-13977","description":"[en] The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in all versions up to, and including, 6.5.3. This is due to insufficient input sanitization and output escaping in the Event Calendar widget's custom attributes handling and the Image Masking module's element ID rendering. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-12-17"},{"id":"b9e972053d0085068de6555e4e06d926f9c14857","name":"Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-popular-elementor-templates-widgets-653-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in all versions up to, and including, 6.5.3. This is due to insufficient input sanitization and output escaping in the Event Calendar widget's custom attributes handling and the Image Masking module's element ID rendering. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-12-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6400ce19f486575e400b8b42160608e087d7cf4634f58fee5cfe5234d026c213","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-69092","name":"CVE-2025-69092","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-69092","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows DOM-Based XSS.This issue affects Essential Addons for Elementor: from n\/a through <= 6.5.3.","date":"2025-12-30"},{"id":"2b0fcfba408a938203992c1739fd49fefbc1b0af","name":"Essential Addons for Elementor <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-653-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-01-06"},{"id":"EUVD-2025-205706","name":"EUVD-2025-205706","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-205706","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows DOM-Based XSS.This issue affects Essential Addons for Elementor: from n\/a through <= 6.5.3.","date":"2025-12-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"3.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"3.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"eeb933583a0e159e97e16f4764f3b020631f28a6825cc45914dc21c279e5393d","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.5.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-23543","name":"CVE-2026-23543","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-23543","description":"[en] Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n\/a through <= 6.5.5.","date":"2026-02-19"},{"id":"af188b1fb2bdc829d0c1a546d09d550a96d07e80","name":"Essential Addons for Elementor <= 6.5.5 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-655-missing-authorization","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.5.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2025-11-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9c0c7400bc7aa03ba796ac61000d66dcccea7f2b14cb9d7123e53d32d869904e","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.5.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1512","name":"Essential Addons for Elementor <= 6.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1512","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Info Box widget in all versions up to, and including, 6.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"a68fc692709318768686f6216ecbc681054e3028","name":"Essential Addons for Elementor <= 6.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-659-authenticated-contributor-stored-cross-site-scripting-via-info-box-widget","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Info Box widget in all versions up to, and including, 6.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-02-13"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3cd72d12bb5b7eb93663ba6766f37d8f7279a599db71c2cd1ab0f560c1d1abab","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.5.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1004","name":"Essential Addons for Elementor <= 6.5.5 - Missing Authorization to Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1004","description":"The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information for products with draft, pending, or private status, which should normally be restricted.","date":"0000-00-00"},{"id":"990d1b83f5c56a32241f4105fd2d9a55049c150f","name":"Essential Addons for Elementor <= 6.5.5 - Missing Authorization to Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-655-missing-authorization-to-unauthenticated-sensitive-information-exposure","description":"The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information for products with draft, pending, or private status, which should normally be restricted.","date":"2026-01-15"}],"impact":{"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7b71752a40eca5d434f679cfc6af5608bb9b00f822056d0f637dcf5bf8961af6","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.6.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-25440","name":"CVE-2026-25440","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-25440","description":"[en] Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.","date":"2026-06-15"},{"id":"a15896fd99e888b1fadd3651cbe3188dc61c5f2b","name":"Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets < 6.6.0 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-popular-elementor-templates-widgets-660-missing-authorization","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 6.6.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-04-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"89beec89c523f3b7dedf5b23320e973a51c331b169cc6aab2f944d618e11623e","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.6.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5193","name":"CVE-2026-5193","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5193","description":"[en] The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role validation in the 'register_user' function, which only blocks the 'administrator' role. This makes it possible for authenticated attackers, with author level access and above, to create new user accounts with elevated privileges such as editor.","date":"2026-05-14"},{"id":"95c2943337d645e9500fd5d6c06abcdd7a5011b4","name":"Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_user","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-popular-elementor-templates-widgets-6513-authenticated-author-limited-privilege-escalation-via-register-user","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role validation in the 'register_user' function, which only blocks the 'administrator' role. This makes it possible for authenticated attackers, with author level access and above, to create new user accounts with elevated privileges such as editor.","date":"2026-05-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"87aa502f4f8cd20e93b49d024e75e3a25f835571642d32bb4d694e0e6092ac57","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-7665","name":"CVE-2026-7665","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-7665","description":"[en] The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.","date":"2026-06-06"},{"id":"322eaff19bc98ae71fa489da8e434748d7361231","name":"Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-664-missing-authorization-to-unauthenticated-information-exposure-via-load-more-ajax-handler","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.","date":"2026-06-05"},{"id":"EUVD-2026-34950","name":"EUVD-2026-34950","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-34950","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.","date":"2026-06-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"778d0a994b8e385f44aa60556aee55edd18e20b0cb89b9f1dc7a48b1824ad2ca","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.6.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-6459","name":"CVE-2026-6459","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-6459","description":"[en] The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on event titles sourced from The Events Calendar. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-08"},{"id":"cbe7b62edf3f2e52bf8e6a70a3fc677b518f387d","name":"Essential Addons for Elementor <= 6.6.2 - Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-662-authenticated-author-stored-cross-site-scripting-via-event-calendar-widget-popup","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on event titles sourced from The Events Calendar. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b26e856a1237584519bda975fc847ecfc23678569525d9cd92a36ef77dc6e0f7","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.6.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15155","name":"CVE-2026-15155","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15155","description":"[en] The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login\/Register widget setting used to construct outgoing email headers \u2014 the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR\/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail headers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link, and achieve full administrator account takeover.","date":"2026-07-11"},{"id":"bbad6d3569ef8ed74be72e81db6430b9d3cfa253","name":"Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/cbe8cf6c-b1fa-4f71-bb63-c8b181e54882","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10. This is due to insufficient server-side validation of a Login\/Register widget setting used to construct outgoing email headers \u2014 the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR\/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail headers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link, and achieve full administrator account takeover.","date":"2026-07-10"},{"id":"EUVD-2026-43160","name":"EUVD-2026-43160","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-43160","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login\/Register widget setting used to construct outgoing email headers \u2014 the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR\/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail headers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link, and achieve full administrator account takeover.","date":"2026-07-11"},{"id":"b652cf10e86745ff72a5b69834903bb5c1e68f56","name":"Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-6610-authenticated-contributor-account-takeover-via-email-header-injection","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10. This is due to insufficient server-side validation of a Login\/Register widget setting used to construct outgoing email headers \u2014 the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR\/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail headers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link, and achieve full administrator account takeover.","date":"2026-07-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-640","name":"Weak Password Recovery Mechanism for Forgotten Password","description":"The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null},"epss":"0.004"}},{"uuid":"d441a79c199eac50dc8ab3b0dc22d556d8d188048cf058c5e21c8c8b23fd63e8","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15145","name":"CVE-2026-15145","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15145","description":"[en] The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-21"},{"id":"9ba5216077ff904506c571c5a9953d4b44f56c1f","name":"Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-6611-authenticated-contributor-stored-cross-site-scripting-via-fancy-text-widget","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"11a168b854c93ecf2e565bb1621ea572f1c32b9b342280ec1a09ce25b5853935","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15156","name":"CVE-2026-15156","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15156","description":"[en] The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-21"},{"id":"4fb4a665985754a9bd050cb38a3b990856544cde","name":"Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/dde0cf3a-778b-4b5f-ac0e-600505d918ae","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-20"},{"id":"ae0217625fcb813e92b08acbd8b2f835355f61a5","name":"Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-6611-authenticated-contributor-stored-cross-site-scripting-via-reading-progress-global-color-settings","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4f92cf776374a53b0fe94fc0e8784444d1a0518f28ee48033982894fce8d4b35","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.6.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-13345","name":"CVE-2026-13345","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-13345","description":"[en] The Essential Addons for Elementor  WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are otherwise withheld from public view.","date":"2026-07-30"},{"id":"8b5cdde4f732cc234cf9fe1cc2ec2c30ba508880","name":"Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets < 6.6.10 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/0f38e5f0-6c62-4c0a-99f9-09bc20ee87d4","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 6.6.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-07-30"},{"id":"8b51c6e98a5a7c8bfe50e9d27158989a943d1e00","name":"Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets < 6.6.10 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-popular-elementor-templates-widgets-6610-missing-authorization","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 6.6.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-07-30"}],"impact":{"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"694bdb7b0850b49ae362c97bf7adb904e751adb4380a16af14680b803fb604c6","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.6.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.6.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-13344","name":"CVE-2026-13344","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-13344","description":"[en] The Essential Addons for Elementor  WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed, including in the session of an administrator previewing or visiting the post.","date":"2026-07-30"},{"id":"1efa030748c65445a43162d05d7c7fe61db388d9","name":"Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets < 6.6.10 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-popular-elementor-templates-widgets-6610-authenticated-contributor-stored-cross-site-scripting","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6.6.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-30"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"15ea635ed4aa7e1d77cafa8db243ae515c0c403340527097d3d918112931aa6b","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.7.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.7.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-18039","name":"CVE-2026-18039","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-18039","description":"[en] The Essential Addons for Elementor  WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.","date":"2026-08-14"},{"id":"df69b33ad71d674ae633d70e245e009965da30ca","name":"Essential Addons for Elementor <= 6.7.1 - Unauthenticated Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-671-unauthenticated-privilege-escalation","description":"The Essential Addons for Elementor plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.1. This is due to missing validation against reserved wp_insert_user() data keys (such as 'role') when building the custom profile fields array, allowing user-controlled field labels to overwrite core user properties via mass assignment. This makes it possible for unauthenticated attackers to register as a new user with an arbitrary role, including administrator, by submitting a custom profile field whose label slugifies to 'role' (or another reserved wp_insert_user key), causing the value to be passed directly to wp_insert_user().","date":"2026-07-30"}],"impact":{"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"211080d6f89427eee6b7cfb0b16aeb671a4174e2d5859611679279295664f6e0","name":"Essential Addons for Elementor &#8211; Popular Elementor Templates &amp; Widgets [essential-addons-for-elementor-lite] < 6.8.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-81777","name":"CVE-2026-81777","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-81777","description":"[en] Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing.\n\nThis issue affects Essential Addons for Elementor: from n\/a through 6.8.0.","date":"2026-08-28"},{"id":"856ac22bdd7527e008643832985588312ce11eb6","name":"Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets <= 6.8.0 - Unauthenticated Captcha Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/essential-addons-for-elementor-lite\/essential-addons-for-elementor-popular-elementor-templates-widgets-680-unauthenticated-captcha-bypass","description":"The Essential Addons for Elementor \u2013 Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Captcha Bypass in all versions up to, and including, 6.8.0. This makes it possible for unauthenticated attackers to bypass Captcha.","date":"2026-08-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-290","name":"Authentication Bypass by Spoofing","description":"This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1788417946"}