← WordPress Vulnerabilities
WordPress security by component

ElementsKit Pro

ElementsKit Pro is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Jan 28, 2025; the highest CVE/CNA score is 8.8.

Plugin slug: elementskit

CVE-2025-0321: ElementsKit Pro: Cross-site scripting

ElementsKit Pro is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedJan 28, 2025
Safe version guidanceSee mitigation notes
Safe version
Jan 28, 2025 CVE-2025-0321
ElementsKit Pro: Cross-site scripting
ElementsKit Pro is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Sep 23, 2024 CVE-2024-43996
ElementsKit Pro: Filesystem traversal
ElementsKit Pro is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.5
NVD6.5
Aug 15, 2024 CVE-2024-7064
ElementsKit Pro: Cross-site scripting
ElementsKit Pro is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Aug 15, 2024 CVE-2024-7063
ElementsKit Pro: Sensitive information exposure
ElementsKit Pro is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVDPending
Jun 15, 2024 CVE-2024-5263
ElementsKit Pro: Cross-site scripting
ElementsKit Pro is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 14, 2024 CVE-2024-4404
ElementsKit PRO: Server-side request forgery
ElementsKit PRO is affected by server-side request forgery. Exploitation requires an authenticated WordPress account. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE8.5
NVD9.6
May 21, 2024 CVE-2024-4452
ElementsKit Pro: Cross-site scripting
ElementsKit Pro is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-3500
ElementsKit Pro: Filesystem traversal
ElementsKit Pro is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVDPending
Apr 19, 2024 CVE-2024-3598
ElementsKit Pro: Cross-site scripting
ElementsKit Pro is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4