cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forgum-elementor-addon gum-elementor-addon

Direction: ascending
Jun 07, 2024

Gum Elementor Addon # CVE-2024-4668

CVE, Research URL

CVE-2024-4668

Application

Gum Elementor Addon

Date
May 30, 2024
Research Description
The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Price Table and Post Slider widgets in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Gum Elementor Addon # CVE-2024-2348

CVE, Research URL

CVE-2024-2348

Application

Gum Elementor Addon

Date
Apr 10, 2024
Research Description
The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Meta widget in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Jul 12, 2024

Gum Elementor Addon # CVE-2024-37565

CVE, Research URL

CVE-2024-37565

Application

Gum Elementor Addon

Date
Jul 20, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TemeGUM Gum Elementor Addon allows Stored XSS.This issue affects Gum Elementor Addon: from n/a through 1.3.5.
Affected versions
Min -, max -.
Status
vulnerable
Sep 28, 2024

Gum Elementor Addon # CVE-2024-44027

CVE, Research URL

CVE-2024-44027

Application

Gum Elementor Addon

Date
Oct 06, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TemeGUM Gum Elementor Addon allows Stored XSS.This issue affects Gum Elementor Addon: from n/a through 1.3.6.
Affected versions
Min -, max -.
Status
vulnerable

Gum Elementor Addon # CVE-2024-44035

CVE, Research URL

CVE-2024-44035

Application

Gum Elementor Addon

Date
Oct 06, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TemeGUM Gum Elementor Addon allows Stored XSS.This issue affects Gum Elementor Addon: from n/a through 1.3.7.
Affected versions
Min -, max -.
Status
vulnerable
Apr 01, 2025

Gum Elementor Addon # CVE-2025-30800

CVE, Research URL

CVE-2025-30800

Application

Gum Elementor Addon

Date
Mar 27, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon allows Stored XSS. This issue affects Gum Elementor Addon: from n/a through 1.3.10.
Affected versions
Min -, max -.
Status
vulnerable