Cross-Site Scripting

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-4643 | WordPress Plugin Vulnerability Report

By Your WP Guy / Aug 1, 2024

Plugin Name: Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Key Information: Software Type: Plugin Software Slug: bdthemes-element-pack-lite Software Status: Active Software Author: bdthemes Software Downloads: 2,552,973 Active Installs: 100,000 Last Updated: August 12, 2024 Patched Versions: 5.6.12 Affected Versions: <= 5.6.11 Vulnerability Details: Name: Element Pack Elementor Addons…

Read More

Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Vulnerability – Authenticated (Subscriber+) Stored Cross-Site Scripting – CVE-2024-6725 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 30, 2024

Plugin Name: Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Key Information: Software Type: Plugin Software Slug: formidable Software Status: Active Software Author: strategy11team Software Downloads: 21,415,029 Active Installs: 400,000 Last Updated: August 6, 2024 Patched Versions: 6.11.2 Affected Versions: <= 6.11.1 Vulnerability Details: Name: Formidable Forms <=…

Read More

Download Manager Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode – CVE-2024-6208 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 30, 2024

Plugin Name: Download Manager Key Information: Software Type: Plugin Software Slug: download-manager Software Status: Active Software Author: codename065 Software Downloads: 8,808,376 Active Installs: 100,000 Last Updated: August 12, 2024 Patched Versions: 3.2.98 Affected Versions: <= 3.2.97 Vulnerability Details: Name: Download Manager <= 3.2.97 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Type: Stored Cross-Site Scripting…

Read More

SiteOrigin Widgets Bundle Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting in Image Grid Widget – CVE-2024-5901 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 30, 2024

Plugin Name: SiteOrigin Widgets Bundle Key Information: Software Type: Plugin Software Slug: so-widgets-bundle Software Status: Active Software Author: gpriday Software Downloads: 40,680,217 Active Installs: 600,000 Last Updated: August 12, 2024 Patched Versions: 1.62.3 Affected Versions: <= 1.62.2 Vulnerability Details: Name: SiteOrigin Widgets Bundle <= 1.62.2 Title: Authenticated (Contributor+) Stored Cross-Site Scripting in Image Grid Widget…

Read More

Happy Addons for Elementor Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via PDF View Widget – CVE-2024-6627 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 26, 2024

Plugin Name: Happy Addons for Elementor Key Information: Software Type: Plugin Software Slug: happy-elementor-addons Software Status: Active Software Author: thehappymonster Software Downloads: 7,563,441 Active Installs: 400,000 Last Updated: July 29, 2024 Patched Versions: 3.11.3 Affected Versions: <= 3.11.2 Vulnerability Details: Name: Happy Addons for Elementor <= 3.11.2 Type: Authenticated (Contributor+) Stored Cross-Site Scripting via PDF…

Read More

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Vulnerability – Multiple Stored Cross-Site Scripting Vulnerabilities – CVE-2024-6703, CVE-2024-6521, CVE-2024-6518, CVE-2024-6520 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 26, 2024

Plugin Name: Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Key Information: Software Type: Plugin Software Slug: fluentform Software Status: Active Software Author: techjewel Software Downloads: 7,722,361 Active Installs: 400,000 Last Updated: August 12, 2024 Patched Versions: 5.1.20 Affected Versions: <= 5.1.19 Vulnerability 1 Details: Name: Contact…

Read More

Royal Elementor Addons and Templates Vulnerability – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget – CVE-2024-5818 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 23, 2024

Plugin Name: Royal Elementor Addons and Templates Key Information: Software Type: Plugin Software Slug: royal-elementor-addons Software Status: Active Software Author: wproyal Software Downloads: 6,367,071 Active Installs: 400,000 Last Updated: July 29, 2024 Patched Versions: 1.3.981 Affected Versions: <= 1.3.980 Vulnerability Details: Name: Royal Elementor Addons and Templates <= 1.3.980 Type: Authenticated (Contributor+) DOM-Based Stored Cross-Site…

Read More

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Vulnerability – Multiple Authenticated (Contributor+) Stored Cross-Site Scripting Vulnerabilities – CVE-2024-5554, CVE-2024-5555 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 17, 2024

Plugin Name: Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Key Information: Software Type: Plugin Software Slug: bdthemes-element-pack-lite Software Status: Active Software Author: bdthemes Software Downloads: 2,552,973 Active Installs: 100,000 Last Updated: August 12, 2024 Patched Versions: 5.6.12, 5.6.6 Affected Versions: <= 5.6.11, <= 5.6.5 Vulnerability 1 Details: Name:…

Read More

User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Vulnerability – Unauthenticated Stored Cross-Site Scripting via Name Parameter – CVE-2024-5902 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 12, 2024

Plugin Name: User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Key Information: Software Type: Plugin Software Slug: userfeedback-lite Software Status: Active Software Author: smub Software Downloads: 1,961,766 Active Installs: 200,000 Last Updated: August 8, 2024 Patched Versions: 1.0.16 Affected Versions: <= 1.0.15 Vulnerability Details: Name: UserFeedback Lite <= 1.0.15 Title:…

Read More

Premium Addons for Elementor Vulnerability – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Animated Text Widget – CVE-2024-6495 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jul 11, 2024

Plugin Name: Premium Addons for Elementor Key Information: Software Type: Plugin Software Slug: premium-addons-for-elementor Software Status: Active Software Author: leap13 Software Downloads: 33,726,442 Active Installs: 700,000 Last Updated: July 27, 2024 Patched Versions: 4.10.37 Affected Versions: <= 4.10.36 Vulnerability Details: Name: Premium Addons for Elementor <= 4.10.36 Type: Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via…

Read More