cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forexclusive-addons-for-elementor exclusive-addons-for-elementor

Direction: ascending
Jun 07, 2024

Exclusive Addons for Elementor # CVE-2024-0824

CVE, Research URL

CVE-2024-0824

Date
Jan 27, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Anything functionality in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-1414

CVE, Research URL

CVE-2024-1414

Date
Mar 13, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Action widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-2028

CVE, Research URL

CVE-2024-2028

Date
Mar 13, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Covid-19 Stats Widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-32110

CVE, Research URL

CVE-2024-32110

Date
-
Research Description
Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.1 CVE-2024-32110
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-2751

CVE, Research URL

CVE-2024-2751

Date
May 02, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exad_infobox_animating_mask_style’ parameter in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2022-45067

CVE, Research URL

CVE-2022-45067

Date
Feb 03, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in DevsCred Exclusive Addons Elementor plugin <= 2.6.1 versions.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-1234

CVE, Research URL

CVE-2024-1234

Date
Mar 13, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-0823

CVE, Research URL

CVE-2024-0823

Date
Feb 06, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' url in carousels in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-2503

CVE, Research URL

CVE-2024-2503

Date
May 02, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid Widget in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping on user supplied tags. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32557 is likely a duplicate of this issue.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-32557

CVE, Research URL

CVE-2024-32557

Date
Apr 16, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.2.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-1413

CVE, Research URL

CVE-2024-1413

Date
Mar 13, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-30232

CVE, Research URL

CVE-2024-30232

Date
Mar 26, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-30177

CVE, Research URL

CVE-2024-30177

Date
Mar 27, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.8.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-2750

CVE, Research URL

CVE-2024-2750

Date
May 02, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of the Button widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-3985

CVE, Research URL

CVE-2024-3985

Date
May 02, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Call to Action widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-33914

CVE, Research URL

CVE-2024-33914

Date
May 03, 2024
Research Description
Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.1.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-3489

CVE, Research URL

CVE-2024-3489

Date
May 02, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Countdown Expired Title in all versions up to, and including, 2.6.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable

Exclusive Addons for Elementor # CVE-2024-4618

CVE, Research URL

CVE-2024-4618

Date
May 15, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member widget in all versions up to, and including, 2.6.9.6 due to insufficient input sanitization and output escaping on user supplied 'url' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Jun 27, 2024

Exclusive Addons for Elementor # CVE-2024-5332

CVE, Research URL

CVE-2024-5332

Date
Jun 26, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Card widget in all versions up to, and including, 2.6.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Oct 18, 2024

Exclusive Addons for Elementor # CVE-2024-49292

CVE, Research URL

CVE-2024-49292

Date
Oct 18, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.7.1.
Affected versions
Min -, max -.
Status
vulnerable
Oct 29, 2024

Exclusive Addons for Elementor # CVE-2024-10312

CVE, Research URL

CVE-2024-10312

Date
Oct 29, 2024
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.4 via the render function in elements/tabs/tabs.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
Affected versions
Min -, max -.
Status
vulnerable
Mar 01, 2025

Exclusive Addons for Elementor # CVE-2025-1571

CVE, Research URL

CVE-2025-1571

Date
Feb 28, 2025
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Image Comparison Widgets in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
May 30, 2025

Exclusive Addons for Elementor # CVE-2025-4783

CVE, Research URL

CVE-2025-4783

Date
May 27, 2025
Research Description
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attributes of the Countdown Timer Widget in all versions up to, and including, 2.7.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable