POSIMYTH Vulnerabilities and Affected Products
Vulnerabilities associated with the_plus_addons_for_elementor.
Products
Clear product- Nexter Blocks8 vulnerabilities
- The Plus Addons for Elementor Page Builder Lite8 vulnerabilities
- the_plus_addons_for_elementor4 vulnerabilities
- Nexter2 vulnerabilities
- Nexter Extension2 vulnerabilities
- UiChemy2 vulnerabilities
- nexter_blocks1 vulnerability
- Sticky Header Effects for Elementor1 vulnerability
- the_plus_addons_for_elementor_pro1 vulnerability
- WDesignkit1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-43932MEDIUM | WordPress The Plus Addons for Elementor plugin <= 5.6.2 - Broken Access Control vulnerabilityMissing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through <= 5.6.2. CWE-862Nov 1, 2024 | CVSS6.5v3.1 | EPSS0.569% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-0445MEDIUM | The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site ScriptingThe The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-34373 is likely a duplicate of this issue. CWE-79May 9, 2024 | CVSS6.4v3.1 | EPSS0.539% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-4332MEDIUM | The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File ReadThe Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box. Unfortunately, the plugin used file_get_contents with no verification that the file being supplied was an SVG file, so any user with access to the Elementor page builder, such as contributors, could read arbitrary files … CWE-73Mar 7, 2023 | CVSS6.5v3.1 | EPSS0.796% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24175CRITICAL | The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication BypassThe Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active. | CVSS9.8v3.1 | EPSS14.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |