Vulnerability index

Browse CVEs

73 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ht Mega MEDIUM 5.4
CVE-2024-3990

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip & Popover Widget in all…

Fix: 2.5.1+
Fix from $1,600 2024-05-14
Ht Mega MEDIUM 5.4
CVE-2024-3989

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gallery Justify Widget…

Fix: 2.5.1+
Fix from $1,600 2024-05-14
Shoplentor MEDIUM 5.3
CVE-2023-6327

The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purcha…

Fix: 2.8.8+
Fix from $1,600 2024-05-14
Shoplentor MEDIUM 5.4
CVE-2024-3991

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera…

Fix: 2.8.8+
Fix from $1,600 2024-05-02
Ht Mega MEDIUM 5.4
CVE-2024-3307

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget's attributes i…

Fix: 2.5.0+
Fix from $1,600 2024-05-02
Ht Mega MEDIUM 5.4
CVE-2024-3308

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget's attributes …

Fix: 2.5.0+
Fix from $1,600 2024-05-02
Ht Mega MEDIUM 5.4
CVE-2024-2790

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Accordion widget in all versions up…

Fix: 2.4.9+
Fix from $1,600 2024-05-02
Ht Mega MEDIUM 5.4
CVE-2024-2084

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lightbox widget in all…

Fix: 2.4.7+
Fix from $1,600 2024-05-02
Ht Mega MEDIUM 5.4
CVE-2024-2085

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' value in several widgets…

Fix: 2.4.7+
Fix from $1,600 2024-05-02
Ht Mega HIGH 7.5
CVE-2023-6214

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including…

Fix: 2.4.7+
Fix from $1,950 2024-05-02
Ht Mega MEDIUM 6.5
CVE-2024-32782

Insertion of Sensitive Information Into Sent Data vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a throug…

Fix: 2.4.8+
Fix from $1,600 2024-04-24
Shoplentor MEDIUM 5.4
CVE-2024-1057

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera…

Fix: 2.8.2+
Fix from $1,600 2024-04-20
Shoplentor MEDIUM 5.4
CVE-2024-2946

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera…

Fix: 2.8.5+
Fix from $1,600 2024-04-09
Ht Mega MEDIUM 6.5
CVE-2024-1974

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via…

Fix: 2.4.7+
Fix from $1,600 2024-04-09
Shoplentor MEDIUM 5.4
CVE-2024-1960

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera…

Fix: 2.8.2+
Fix from $1,600 2024-04-09
Shoplentor MEDIUM 6.4
CVE-2024-2868

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera…

Fix: 2.8.4+
Fix from $1,600 2024-04-04
Ht Mega MEDIUM 5.4
CVE-2024-30182

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems HT Mega ht-mega-for-elementor.This iss…

Fix: 2.4.4+
Fix from $1,600 2024-03-27
Wc Builder MEDIUM 5.4
CVE-2024-29926

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WC Builder allows Stored XSS.This iss…

Fix: 1.0.19+
Fix from $1,600 2024-03-27
Wishsuite MEDIUM 5.4
CVE-2024-29927

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasTheme WishSuite allows Stored XSS.This issue…

Fix: 1.3.8+
Fix from $1,600 2024-03-27
Ht Easy Ga4 \(google Analytics 4\) MEDIUM 6.1
CVE-2024-29094

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) al…

Fix: 1.1.8+
Fix from $1,600 2024-03-19
Extensions For Cf7 MEDIUM 6.1
CVE-2024-29102

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes Extensions For CF7 allows Stored XSS.…

Fix: 3.0.7+
Fix from $1,600 2024-03-19
Ht Easy Ga4 MEDIUM 5.3
CVE-2024-1176

The HT Easy GA4 – Google Analytics WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili…

Fix: 1.2.0+
Fix from $1,600 2024-03-13
Ht Mega MEDIUM 5.4
CVE-2024-1397

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions…

Fix: 2.4.7+
Fix from $1,600 2024-03-12
Ht Mega MEDIUM 5.4
CVE-2024-1421

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the …

Fix: after 2.4.4
Fix from $1,600 2024-03-12
Ht Mega HIGH 8.8
CVE-2023-51529

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Mega – Absolute Addons For Elementor.This issue affects HT Mega – Absolute Addons For…

Fix: 2.3.4+
Fix from $1,950 2024-02-29
Ht Mega MEDIUM 6.1
CVE-2023-50901

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega – Absolute Addons For Element…

Fix: after 2.3.8
Fix from $1,600 2023-12-29
Woolentor Woocommerce Elementor Addons \+ Builder HIGH 8.8
CVE-2022-47172

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.6.2 versions.

Fix: after 2.6.2
Fix from $1,950 2023-07-17
Wishsuite HIGH 8.8
CVE-2023-23731

Cross-Site Request Forgery (CSRF) vulnerability in HasTheme WishSuite plugin <= 1.3.3 versions.

Fix: 1.3.4+
Fix from $1,950 2023-07-11
Justtables HIGH 8.8
CVE-2023-23803

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes JustTables plugin <= 1.4.9 versions.

Fix: 1.5.0+
Fix from $1,950 2023-07-11
Ht Menu HIGH 8.8
CVE-2023-23791

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Menu plugin <= 1.2.1 versions.

Fix: 1.2.2+
Fix from $1,950 2023-07-11