Elementskit
Wpmet · 9 CVEs
ElementsKit Pro <= 3.7.8 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via url Parameter
Jan 28, 2025
WordPress ElementsKit Pro plugin <= 3.6.0 - Local File Inclusion vulnerability
Sep 23, 2024
ElementsKit Pro <= 3.6.6 - Authenticated (Contributor+) Sensitive Information Exposure
Aug 15, 2024
ElementsKit Pro <= 3.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Aug 15, 2024
ElementsKit Elementor addons and Templates Library <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting…
Jun 15, 2024
ElementsKit PRO <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery
Jun 14, 2024
ElementsKit Pro <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
May 21, 2024
ElementsKit Pro <= 3.6.0 - Authenticated (Contributor+) Local File Inclusion via Price Menu, Hotspot, and Advanced Togg…
May 2, 2024
ElementsKit Pro <= 3.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ekit_btn_id'
Apr 19, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-0321 | ElementsKit Pro <= 3.7.8 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via url Parameter | MEDIUM | 0.26% | Jan 28, 2025 |
| CVE-2024-43996 | WordPress ElementsKit Pro plugin <= 3.6.0 - Local File Inclusion vulnerability | MEDIUM | 0.62% | Sep 23, 2024 |
| CVE-2024-7063 | ElementsKit Pro <= 3.6.6 - Authenticated (Contributor+) Sensitive Information Exposure | MEDIUM | 0.35% | Aug 15, 2024 |
| CVE-2024-7064 | ElementsKit Pro <= 3.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting | MEDIUM | 0.26% | Aug 15, 2024 |
| CVE-2024-5263 | ElementsKit Elementor addons and Templates Library <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Motion Text and Table Widgets | MEDIUM | 0.26% | Jun 15, 2024 |
| CVE-2024-4404 | ElementsKit PRO <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery | CRITICAL | 0.32% | Jun 14, 2024 |
| CVE-2024-4452 | ElementsKit Pro <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | MEDIUM | 0.26% | May 21, 2024 |
| CVE-2024-3500 | ElementsKit Pro <= 3.6.0 - Authenticated (Contributor+) Local File Inclusion via Price Menu, Hotspot, and Advanced Toggle Widgets | HIGH | 1.06% | May 2, 2024 |
| CVE-2024-3598 | ElementsKit Pro <= 3.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ekit_btn_id' | MEDIUM | 0.32% | Apr 19, 2024 |
Showing 1 to 9 of 9 CVEs