WordPress Elementor 漏洞列表
共找到 10 个与 WordPress Elementor 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2022-29455-headless: WordPress Elementor Website Builder <= 3.5.5 - DOM Cross-Site Scripting POC
WordPress Elementor Website Builder plugin 3.5.5 and prior contains a reflected cross-site scripting vulnerability via the document object model. -
CVE-2021-24891: WordPress Elementor Website Builder <3.1.4 - Cross-Site Scripting POC
WordPress Elementor Website Builder plugin before 3.1.4 contains a DOM cross-site scripting vulnerability. It does not sanitize or escape user input appended to the DOM via a malicious hash. -
CVE-2022-29455: WordPress Elementor Website Builder <= 3.5.5 - DOM Cross-Site Scripting POC
WordPress Elementor Website Builder plugin 3.5.5 and prior contains a reflected cross-site scripting vulnerability via the document object model. -
CVE-2023-32243: WordPress Elementor Lite 5.7.1 - Arbitrary Password Reset POC
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1. -
CVE-2023-48777: WordPress Elementor 3.18.1 - File Upload/Remote Code Execution POC
The plugin is vulnerable to Remote Code Execution via file upload via the template import functionality, allowing authenticated attackers, with contributor-level access and above, to upload files and execute code on the server. -
CVE-2022-29455-headless: WordPress Elementor Website Builder <= 3.5.5 - DOM Cross-Site Scripting POC
WordPress Elementor Website Builder plugin 3.5.5 and prior contains a reflected cross-site scripting vulnerability via the document object model. -
CVE-2021-24891: WordPress Elementor Website Builder <3.1.4 - Cross-Site Scripting POC
WordPress Elementor Website Builder plugin before 3.1.4 contains a DOM cross-site scripting vulnerability. It does not sanitize or escape user input appended to the DOM via a malicious hash. -
CVE-2022-29455: WordPress Elementor Website Builder <= 3.5.5 - DOM Cross-Site Scripting POC
WordPress Elementor Website Builder plugin 3.5.5 and prior contains a reflected cross-site scripting vulnerability via the document object model. -
CVE-2023-32243: WordPress Elementor Lite 5.7.1 - Arbitrary Password Reset POC
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1. -
CVE-2023-48777: WordPress Elementor 3.18.1 - File Upload/Remote Code Execution POC
The plugin is vulnerable to Remote Code Execution via file upload via the template import functionality, allowing authenticated attackers, with contributor-level access and above, to upload files and execute code on the server.