WPDeveloper Vulnerabilities and Affected Products
Vulnerabilities associated with essential_addons_for_elementor.
Products
Clear product- Essential Addons for Elementor11 vulnerabilities
- EmbedPress9 vulnerabilities
- Essential Blocks for Gutenberg8 vulnerabilities
- BetterDocs6 vulnerabilities
- essential_addons_for_elementor5 vulnerabilities
- Templately5 vulnerabilities
- NotificationX3 vulnerabilities
- BetterLinks2 vulnerabilities
- Essential Addons for Elementor Pro2 vulnerabilities
- essential_blocks2 vulnerabilities
- SchedulePress2 vulnerabilities
- Typing Text2 vulnerabilities
- Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More1 vulnerability
- Document Block – Upload & Embed Docs1 vulnerability
- Essential Addons for Elementor plugin for WordPress1 vulnerability
- Parallax Slider Block1 vulnerability
- ReviewX – Multi-criteria Rating & Reviews for WooCommerce1 vulnerability
- Secret Meta1 vulnerability
- Simple 301 Redirects by BetterLinks1 vulnerability
- simple_301_redirects1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-8979HIGH | Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege EscalationThe Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_lostpassword_user_email_controls' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including usernames and passwords of any user, including Administrators, as long as that user opens … CWE-200Nov 15, 2024 | CVSS8.0v3.1 | EPSS0.493% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-4447HIGH | Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege EscalationThe Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Elementor page builder to create a new registration form that defaults to the user role being set to administrator and subsequently register as an administrative user. CWE-862Oct 16, 2024 | CVSS8.8v3.1 | EPSS0.457% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-3733MEDIUM | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Information ExposureThe Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery() functions. This makes it possible for unauthenticated attackers to extract posts that may be in private or draft status. | CVSS5.3v3.1 | EPSS0.496% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-3018HIGH | Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpasswordThe Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the "Login | Register Form" widget (disabled by default). This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow t… CWE-502Mar 30, 2024 | CVSS8.8v3.1 | EPSS0.775% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-32243CRITICAL | WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege EscalationImproper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1. | CVSS9.8v3.1 | EPSS75.5% | PoCs7 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |