cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forenteraddons enteraddons

Direction: ascending
Jun 07, 2024

Enter Addons – Ultimate Template Builder for Elementor # CVE-2024-3680

CVE, Research URL

CVE-2024-3680

Date
May 14, 2024
Research Description
The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animation Title widget's img tag in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.1.6.
Status
vulnerable

Enter Addons – Ultimate Template Builder for Elementor # CVE-2024-3831

CVE, Research URL

CVE-2024-3831

Date
May 14, 2024
Research Description
The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.1.6.
Status
vulnerable
Jul 01, 2024

Enter Addons – Ultimate Template Builder for Elementor # CVE-2024-37263

CVE, Research URL

CVE-2024-37263

Date
Jul 22, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeLooks Enter Addons enteraddons allows Stored XSS.This issue affects Enter Addons: from n/a through 2.1.6.
Affected versions
max 2.1.7.
Status
vulnerable
Aug 13, 2024

Enter Addons – Ultimate Template Builder for Elementor # CVE-2024-43225

CVE, Research URL

CVE-2024-43225

Date
Aug 13, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeLooks Enter Addons allows Stored XSS.This issue affects Enter Addons: from n/a through 2.1.7.
Affected versions
max 2.2.0.
Status
vulnerable
Sep 07, 2024

Enter Addons – Ultimate Template Builder for Elementor # CVE-2024-7611

CVE, Research URL

CVE-2024-7611

Date
Sep 06, 2024
Research Description
The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute of the Events Card widget in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.1.9.
Status
vulnerable
Oct 03, 2024

Enter Addons – Ultimate Template Builder for Elementor # CVE-2024-47625

CVE, Research URL

CVE-2024-47625

Date
Oct 05, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeLooks Enter Addons allows Stored XSS.This issue affects Enter Addons: from n/a through 2.1.8.
Affected versions
max 2.1.9.
Status
vulnerable
Nov 25, 2024

Enter Addons – Ultimate Template Builder for Elementor # CVE-2024-10868

CVE, Research URL

CVE-2024-10868

Date
Nov 23, 2024
Research Description
The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.9 via the Advanced Tabs widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.
Affected versions
max 2.2.0.
Status
vulnerable
Jan 03, 2025

Enter Addons – Ultimate Template Builder for Elementor # CVE-2024-56252

CVE, Research URL

CVE-2024-56252

Date
Jan 02, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeLooks Enter Addons allows Stored XSS.This issue affects Enter Addons: from n/a through 2.1.9.
Affected versions
max 2.2.1.
Status
vulnerable
Feb 28, 2026

Enter Addons – Ultimate Template Builder for Elementor # CVE-2026-25014

CVE, Research URL

CVE-2026-25014

Date
Feb 03, 2026
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in themelooks Enter Addons enteraddons allows Cross Site Request Forgery.This issue affects Enter Addons: from n/a through <= 2.3.2.
Affected versions
max 2.3.2.
Status
vulnerable