wpmet Vulnerabilities and Affected Products
Vulnerabilities associated with elements_kit_elementor_addons.
Products
Clear product- ElementsKit Pro8 vulnerabilities
- Wp Ultimate Review6 vulnerabilities
- elements_kit_elementor_addons5 vulnerabilities
- MetForm Pro4 vulnerabilities
- ElementsKit Elementor addons Lite2 vulnerabilities
- metform_elementor_contact_form_builder2 vulnerabilities
- wp_fundraising_donation_and_crowdfunding_platform2 vulnerabilities
- wp_ultimate_review2 vulnerabilities
- Elements kit Elementor addons1 vulnerability
- Elements Kit Lite1 vulnerability
- Elements Kit Pro1 vulnerability
- ElementsKit Elementor addons1 vulnerability
- GetGenie1 vulnerability
- gutenkit1 vulnerability
- ShopEngine1 vulnerability
- WP Fundraising Donation and Crowdfunding Platform1 vulnerability
- Wp Social Login and Register Social Counter1 vulnerability
- wp_social_login_and_register_social_counter1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-37255MEDIUM | WordPress ElementsKit Lite plugin <= 3.1.4 - Unauthenticated Broken Access Control vulnerabilityMissing Authorization vulnerability in Roxnor ElementsKit Elementor addons Lite elementskit-lite.This issue affects ElementsKit Elementor addons Lite: from n/a through <= 3.1.4. CWE-862Nov 1, 2024 | CVSS5.3v3.1 | EPSS0.359% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6455MEDIUM | ElementsKit Elementor addons <= 3.2.0 - Unauthenticated Information Exposure via ekit_widgetarea_content FunctionThe ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, pending and private items. | CVSS5.3v3.1 | EPSS0.396% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32505MEDIUM | WordPress ElementsKit Elementor addons plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor ElementsKit Elementor addons Lite elementskit-lite.This issue affects ElementsKit Elementor addons Lite: from n/a through <= 3.0.6. CWE-79Apr 17, 2024 | CVSS6.5v3.1 | EPSS0.291% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-2047HIGH | ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Local File Inclusion in render_rawThe ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the render_raw function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” f… CWE-98Mar 30, 2024 | CVSS8.8v3.1 | EPSS1.48% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24258MEDIUM | ElementsKit and ElementsKit Pro < 2.2.0 - Contributor+ Stored XSSThe Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. CWE-79May 5, 2021 | CVSS5.4v3.1 | EPSS0.626% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |