WordPress security by component
PowerPack Pro for Elementor
Plugin description
PowerPack Pro for Elementor is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jun 08, 2024; the highest CVE/CNA score is 8.8.
Plugin slug:
powerpack-addons-for-elementorLatest vulnerability
CVE-2024-3668: PowerPack Pro for Elementor: Privilege escalation or authentication bypass
PowerPack Pro for Elementor is affected by privilege escalation or authentication bypass. Exploitation requires at least contributor-level access. A successful request can grant permissions or access that the caller should not possess.
| Safe version |
|
||
|---|---|---|---|
| Jun 08, 2024 |
CVE-2024-3668
PowerPack Pro for Elementor: Privilege escalation or authentication bypass
PowerPack Pro for Elementor is affected by privilege escalation or authentication bypass. Exploitation requires at least contributor-level access. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Apr 09, 2024 |
CVE-2024-2492
PowerPack Addons for Elementor: Cross-site scripting
PowerPack Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 30, 2024 |
CVE-2024-2491
PowerPack Addons for Elementor: Cross-site scripting
PowerPack Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 29, 2024 |
CVE-2024-1411
PowerPack Addons for Elementor: Cross-site scripting
PowerPack Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jan 03, 2024 |
CVE-2023-6984
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates): Cross-site request forgery
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.3
NVD4.3
|
| Jan 03, 2022 |
CVE-2021-25027
PowerPack Addons for Elementor: Cross-site scripting
PowerPack Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| May 05, 2021 |
CVE-2021-24263
“Elementor Addons – PowerPack Addons for Elementor”: Cross-site scripting
“Elementor Addons – PowerPack Addons for Elementor” is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|