cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forthe-pack-addon the-pack-addon

Direction: ascending
Jun 06, 2024

The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) # CVE-2024-32718

CVE, Research URL

CVE-2024-32718

Date
Apr 24, 2024
Research Description
Server-Side Request Forgery (SSRF) vulnerability in Webangon The Pack Elementor.This issue affects The Pack Elementor addons: from n/a through 2.0.8.2.
Affected versions
Min -, max -.
Status
vulnerable

The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) # CVE-2024-32785

CVE, Research URL

CVE-2024-32785

Date
Apr 24, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Webangon The Pack Elementor addons allows Cross-Site Scripting (XSS).This issue affects The Pack Elementor addons: from n/a through 2.0.8.3.
Affected versions
Min -, max -.
Status
vulnerable
Jul 20, 2024

The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) # CVE-2024-38768

CVE, Research URL

CVE-2024-38768

Date
Aug 02, 2024
Research Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Webangon The Pack Elementor addons allows PHP Local File Inclusion, Path Traversal.This issue affects The Pack Elementor addons: from n/a through 2.0.8.6.
Affected versions
Min -, max -.
Status
vulnerable
Oct 03, 2024

The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) # CVE-2024-47383

CVE, Research URL

CVE-2024-47383

Date
Oct 05, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webangon The Pack Elementor addons allows Stored XSS.This issue affects The Pack Elementor addons: from n/a through 2.0.8.8.
Affected versions
Min -, max -.
Status
vulnerable
Oct 28, 2024

The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) # CVE-2024-50453

CVE, Research URL

CVE-2024-50453

Date
-
Research Description
The Pack Elementor addons (Header Footer &amp; WooCommerce Builder, Template Library) [the-pack-addon] < 2.1.0 CVE-2024-50453
Affected versions
Min -, max -.
Status
vulnerable
Nov 12, 2024

The Pack Elementor addons (Header Footer &amp; WooCommerce Builder, Template Library) # CVE-2024-52356

CVE, Research URL

CVE-2024-52356

Date
Nov 11, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webangon The Pack Elementor addons allows Stored XSS.This issue affects The Pack Elementor addons: from n/a through 2.1.0.
Affected versions
Min -, max -.
Status
vulnerable
Apr 02, 2025

The Pack Elementor addons (Header Footer &amp; WooCommerce Builder, Template Library) # CVE-2025-30925

CVE, Research URL

CVE-2025-30925

Date
Mar 27, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webangon The Pack Elementor addons allows Stored XSS. This issue affects The Pack Elementor addons: from n/a through 2.1.1.
Affected versions
Min -, max -.
Status
vulnerable

The Pack Elementor addons (Header Footer &amp; WooCommerce Builder, Template Library) # CVE-2025-30845

CVE, Research URL

CVE-2025-30845

Date
Mar 27, 2025
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in webangon The Pack Elementor addons allows PHP Local File Inclusion. This issue affects The Pack Elementor addons: from n/a through 2.1.1.
Affected versions
Min -, max -.
Status
vulnerable
Apr 25, 2025

The Pack Elementor addons (Header Footer &amp; WooCommerce Builder, Template Library) # CVE-2025-46472

CVE, Research URL

CVE-2025-46472

Date
Apr 24, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webangon The Pack Elementor addons allows Stored XSS. This issue affects The Pack Elementor addons: from n/a through 2.1.2.
Affected versions
Min -, max -.
Status
vulnerable