cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches formove-addons move-addons

Direction: ascending
Jun 06, 2024

Move Addons for Elementor # CVE-2024-29920

CVE, Research URL

CVE-2024-29920

Date
Mar 27, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.2.9.
Affected versions
Min -, max -.
Status
vulnerable

Move Addons for Elementor # CVE-2024-30525

CVE, Research URL

CVE-2024-30525

Date
Jun 05, 2024
Research Description
Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor: from n/a through 1.2.9.
Affected versions
Min -, max -.
Status
vulnerable

Move Addons for Elementor # CVE-2024-4695

CVE, Research URL

CVE-2024-4695

Date
May 21, 2024
Research Description
The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Move Addons for Elementor # CVE-2024-2131

CVE, Research URL

CVE-2024-2131

Date
Mar 23, 2024
Research Description
The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's infobox and button widget in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Move Addons for Elementor # CVE-2024-34562

CVE, Research URL

CVE-2024-34562

Date
May 08, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.0.
Affected versions
Min -, max -.
Status
vulnerable
Sep 29, 2024

Move Addons for Elementor # CVE-2024-47396

CVE, Research URL

CVE-2024-47396

Date
Oct 01, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.3.
Affected versions
Min -, max -.
Status
vulnerable
Oct 03, 2024

Move Addons for Elementor # CVE-2024-47364

CVE, Research URL

CVE-2024-47364

Date
Oct 06, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Move addons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.4.
Affected versions
Min -, max -.
Status
vulnerable
Oct 30, 2024

Move Addons for Elementor # CVE-2024-10360

CVE, Research URL

CVE-2024-10360

Date
Oct 29, 2024
Research Description
The Move Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the render function in includes/widgets/accordion/widget.php, includes/widgets/remote-template/widget.php, and other widget.php files. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
Affected versions
Min -, max -.
Status
vulnerable
Jan 03, 2025

Move Addons for Elementor # CVE-2024-56254

CVE, Research URL

CVE-2024-56254

Date
Jan 02, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.6.
Affected versions
Min -, max -.
Status
vulnerable