cleantalk

Vulnerabilities and Security Researches

Vulnerabilities and security researches for wpbits-addons-for-elementor

Direction: ascending

Jun 06, 2024

WPBITS Addons For Elementor Page Builder # CVE-2024-2129

CVE, Research URL

CVE-2024-2129

Date
Mar 20, 2024
Research Description
The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's heading widget in all versions up to, and including, 1.3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

WPBITS Addons For Elementor Page Builder # CVE-2024-32593

CVE, Research URL

CVE-2024-32593

Date
Apr 18, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBits WPBITS Addons For Elementor Page Builder allows Stored XSS.This issue affects WPBITS Addons For Elementor Page Builder: from n/a through 1.3.4.2.
Affected versions
Min -, max -.
Status
vulnerable

WPBITS Addons For Elementor Page Builder # 3be384b4f81fad286dd244400086b969bd3c79f6

Date
Feb 28, 2022
Research Description
WPBITS Addons For Elementor Page Builder [wpbits-addons-for-elementor] < 1.3 WordPress WPBITS Addons For Elementor Page Builder plugin <= 1.3.1 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress WPBITS Addons For Elementor Page Builder plugin (versions <= 1.3.1).
Affected versions
Min -, max -.
Status
vulnerable

Jul 10, 2024

WPBITS Addons For Elementor Page Builder # CVE-2024-4862

CVE, Research URL

CVE-2024-4862

Date
Jul 09, 2024
Research Description
The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Jul 14, 2024

WPBITS Addons For Elementor Page Builder # CVE-2024-37945

CVE, Research URL

CVE-2024-37945

Date
-
Research Description
WPBITS Addons For Elementor Page Builder [wpbits-addons-for-elementor] < 1.5.1 CVE-2024-37945
Affected versions
Min -, max -.
Status
vulnerable

Nov 16, 2024

WPBITS Addons For Elementor Page Builder # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
Min -, max -.
Status
vulnerable

Dec 06, 2024

WPBITS Addons For Elementor Page Builder # CVE-2024-8962

CVE, Research URL

CVE-2024-8962

Date
Dec 04, 2024
Research Description
The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Affected versions
Min -, max -.
Status
vulnerable

Jan 09, 2025

WPBITS Addons For Elementor Page Builder # CVE-2025-22316

CVE, Research URL

CVE-2025-22316

Date
Jan 07, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBits WPBITS Addons For Elementor Page Builder allows Stored XSS.This issue affects WPBITS Addons For Elementor Page Builder: from n/a through 1.5.1.
Affected versions
Min -, max -.
Status
vulnerable

WPBITS Addons For Elementor Page Builder # CVE-2024-56285

CVE, Research URL

CVE-2024-56285

Date
Jan 07, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBits WPBITS Addons For Elementor Page Builder allows Stored XSS.This issue affects WPBITS Addons For Elementor Page Builder: from n/a through 1.5.1.
Affected versions
Min -, max -.
Status
vulnerable