Vulnerability index

Browse CVEs

56 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Elementskit Elementor Addons MEDIUM 5.4
CVE-2025-3614

The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom wi…

Fix: 3.5.3+
Fix from $1,600 2025-07-24
Elementskit Elementor Addons MEDIUM 5.4
CVE-2025-4479

The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin image comparison widg…

Fix: 3.5.3+
Fix from $1,600 2025-06-19
Gutenkit MEDIUM 5.4
CVE-2025-46253

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit gutenkit-blocks-addon allows S…

Fix: 2.2.3+
Fix from $1,600 2025-04-22
Elementskit Elementor Addons MEDIUM 5.4
CVE-2024-11180

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_time…

Fix: 3.4.8+
Fix from $1,600 2025-03-29
Elementskit Elementor Addons MEDIUM 5.3
CVE-2025-0968

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 du…

Fix: 3.4.1+
Fix from $1,600 2025-02-19
Elementskit Elementor Addons MEDIUM 5.4
CVE-2025-1005

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all ver…

Fix: 3.4.1+
Fix from $1,600 2025-02-15
Elementskit MEDIUM 5.4
CVE-2025-0321

The ElementsKit Pro plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and in…

Fix: 3.7.9+
Fix from $1,600 2025-01-28
Metform Elementor Contact Form Builder CRITICAL 9.8
CVE-2023-50903

Missing Authorization vulnerability in Roxnor Metform metform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe…

Fix: 3.4.1+
Fix from $2,300 2024-12-09
Elements Kit Elementor Addons MEDIUM 5.3
CVE-2024-37255

Missing Authorization vulnerability in Roxnor ElementsKit Elementor addons Lite elementskit-lite.This issue affects ElementsKit Elementor addons Lite…

Fix: 3.2.0+
Fix from $1,600 2024-11-01
Elements Kit Elementor Addons MEDIUM 5.4
CVE-2024-10091

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up…

Fix: 3.3.0+
Fix from $1,600 2024-10-26
Elementskit Elementor Addons MEDIUM 5.4
CVE-2024-8546

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up t…

Fix: 3.2.8+
Fix from $1,600 2024-09-25
Elementskit MEDIUM 6.5
CVE-2024-43996

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit Pro allows PHP Local File Inc…

Fix: after 3.6.0
Fix from $1,600 2024-09-23
Metform Elementor Contact Form Builder CRITICAL 9.8
CVE-2023-0714

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions …

Fix: 3.3.0+
Fix from $2,300 2024-08-17
Elementskit MEDIUM 5.4
CVE-2024-7064

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 3.…

Fix: 3.6.6+
Fix from $1,600 2024-08-15
Fundengine HIGH 8.8
CVE-2024-6698

The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not …

Fix: 1.7.1+
Fix from $1,950 2024-08-01
Elements Kit Elementor Addons MEDIUM 5.3
CVE-2024-6455

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a miss…

Fix: 3.2.1+
Fix from $1,600 2024-07-18
Elementskit MEDIUM 5.4
CVE-2024-5263

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and Table widgets in all versions …

Fix: 3.6.3+
Fix from $1,600 2024-06-15
Elementskit CRITICAL 9.6
CVE-2024-4404

The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' fu…

Fix: 3.6.3+
Fix from $2,300 2024-06-14
Metform Elementor Contact Form Builder HIGH 7.5
CVE-2024-4266

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in…

Fix: 3.8.9+
Fix from $1,950 2024-06-11
Elementskit MEDIUM 5.4
CVE-2024-4452

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 3.6.1…

Fix: 3.6.2+
Fix from $1,600 2024-05-21
Wp Ultimate Review MEDIUM 5.3
CVE-2024-32685

Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate …

Fix: 2.3.0+
Fix from $1,600 2024-05-17
Wp Ultimate Review HIGH 7.5
CVE-2024-21746

Authentication Bypass by Spoofing vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows Identity Spoofing.This issue affects Wp Ultima…

Fix: after 2.3.5
Fix from $1,950 2024-05-17
Metform Elementor Contact Form Builder HIGH 8.8
CVE-2024-33570

Missing Authorization vulnerability in Roxnor Metform metform.This issue affects Metform: from n/a through <= 3.8.3.

Fix: 3.8.4+
Fix from $1,950 2024-05-06
Elements Kit Elementor Addons MEDIUM 5.4
CVE-2024-3650

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions 3.0…

Fix: 3.1.3+
Fix from $1,600 2024-05-02
Elementskit HIGH 8.8
CVE-2024-3500

The ElementsKit Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.0 via the Price Menu, Hotspo…

Fix: 3.6.1+
Fix from $1,950 2024-05-02
Elements Kit Elementor Addons HIGH 8.8
CVE-2024-3499

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the gener…

Fix: 3.1.1+
Fix from $1,950 2024-05-02
Wp Ultimate Review HIGH 7.5
CVE-2024-32684

Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

Fix: 2.3.0+
Fix from $1,950 2024-04-22
Wp Ultimate Review HIGH 7.5
CVE-2024-32683

Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.…

Fix: 2.3.0+
Fix from $1,950 2024-04-19
Elementskit MEDIUM 5.4
CVE-2024-3598

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button widget in all versions up to, …

Fix: 3.6.1+
Fix from $1,600 2024-04-19
Elements Kit Elementor Addons MEDIUM 5.4
CVE-2024-32505

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor ElementsKit Elementor addons Lite elemen…

Fix: 3.0.7+
Fix from $1,600 2024-04-17