Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
addons vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2023-49766
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ultimate Addons for Contact Form 7 allows Stored XSS.This issue affects Ultimate Addons for Contact Form 7: from n/a up to and including 3.2.0.
Themefic Ultimate Addons For Contact Form 7
7.2
CVSSv3
CVE-2023-6925
The Unlimited Addons for WPBakery Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'importZipFile' function in versions up to, and including, 1.0.42. This makes it possible for authenticated attack...
Unitecms Unlimited Addons For Wpbakery Page Builder
5.4
CVSSv3
CVE-2023-0268
The Mega Addons For WPBakery Page Builder WordPress plugin prior to 4.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform ...
Topdigitaltrends Mega Addons For Wpbakery Page Builder
6.1
CVSSv3
CVE-2023-30493
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.2.0 versions.
Themefic Ultimate Addons For Contact Form 7
8.8
CVSSv3
CVE-2022-36798
Cross-Site Request Forgery (CSRF) vulnerability in Topdigitaltrends Mega Addons For WPBakery Page Builder plugin <= 4.2.7 at WordPress.
Topdigitaltrends Mega Addons For Wpbakery Page Builder
7.5
CVSSv3
CVE-2023-0159
The Extensive VC Addons for WPBakery page builder WordPress plugin prior to 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated malicious user to override the template path to read arbitrary files from the hos...
Wprealize Extensive Vc Addons For Wpbakery Page Builder
1 Github repository
6.1
CVSSv3
CVE-2023-50901
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega – Absolute Addons For Elementor allows Reflected XSS.This issue affects HT Mega – Absolute Addons For Elementor: from n/a up to and includ...
Hasthemes Ht Mega - Absolute Addons For Elementor Page Builder
6.5
CVSSv3
CVE-2023-31231
Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a up to and including 1.5.65.
Unlimited-elements Unlimited Elements For Elementor \\(free Widgets\\, Addons\\, Templates\\)
8.8
CVSSv3
CVE-2023-3295
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authen...
Unlimited-elements Unlimited Elements For Elementor \\(free Widgets\\, Addons\\, Templates\\)
4.8
CVSSv3
CVE-2022-47170
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.48 versions.
Unlimited-elements Unlimited Elements For Elementor \\(free Widgets\\, Addons\\, Templates\\)
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »