Master-Addons / Master Addons
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-0433 | Master Addons <= 2.0.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter | MEDIUM | 6.4 | Mar 4, 2025 |
| CVE-2024-9618 | Master Addons <= 2.0.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets | MEDIUM | 6.4 | Mar 4, 2025 |
| CVE-2024-9502 | Master Addons -- Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.7 - Authenticated (Contributor+) Stored Cross-Site Scriptin… | MEDIUM | 6.4 | Jan 7, 2025 |
| CVE-2024-6282 | Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting… | MEDIUM | 5.4 | Sep 10, 2024 |
| CVE-2024-38710 | WordPress Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin <= 2.0.6.2 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 5.9 | Jul 20, 2024 |
| CVE-2024-35660 | WordPress Master Addons for Elementor plugin <= 2.0.5.4.1 - Broken Access Control on API vulnerability | CRITICAL | 9.8 | Jun 9, 2024 |
| CVE-2024-35688 | WordPress Master Addons for Elementor plugin <= 2.0.5.9 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | Jun 8, 2024 |
| CVE-2024-35702 | WordPress Master Addons for Elementor plugin <= 2.0.6.0 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | Jun 8, 2024 |
| CVE-2024-5382 | Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to MA Template Creation or Modific… | MEDIUM | 6.5 | Jun 7, 2024 |
| CVE-2024-5542 | Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to Unauthenticated Stored Cross-Si… | HIGH | 7.2 | Jun 7, 2024 |
| CVE-2024-3134 | Master Addons for Elementor <= 2.0.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | MEDIUM | 6.4 | May 16, 2024 |
| CVE-2024-4580 | Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | MEDIUM | 6.4 | May 16, 2024 |
| CVE-2024-4265 | Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.5.9 - Contributor+ Stored Cross-Site Scripting | MEDIUM | 6.4 | May 2, 2024 |
| CVE-2024-33595 | WordPress Master Addons for Elementor plugin <= 2.0.5.4.1 - Broken Access Control on Duplicate Post vulnerability | HIGH | 8.8 | Apr 29, 2024 |
| CVE-2024-29911 | WordPress Master Addons for Elementor plugin <= 2.0.5.4.1 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | Mar 27, 2024 |
| CVE-2024-2139 | Master Addons for Elementor <= 2.0.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget | MEDIUM | 6.4 | Mar 27, 2024 |
Showing 1 to 16 of 16 CVEs