← WordPress Vulnerabilities
WordPress security by component

PowerPack Pro for Elementor

PowerPack Pro for Elementor is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jun 08, 2024; the highest CVE/CNA score is 8.8.

Plugin slug: powerpack-addons-for-elementor

CVE-2024-3668: PowerPack Pro for Elementor: Privilege escalation or authentication bypass

PowerPack Pro for Elementor is affected by privilege escalation or authentication bypass. Exploitation requires at least contributor-level access. A successful request can grant permissions or access that the caller should not possess.

PublishedJun 08, 2024
Safe version guidanceSee mitigation notes
Safe version
Jun 08, 2024 CVE-2024-3668
PowerPack Pro for Elementor: Privilege escalation or authentication bypass
PowerPack Pro for Elementor is affected by privilege escalation or authentication bypass. Exploitation requires at least contributor-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Apr 09, 2024 CVE-2024-2492
PowerPack Addons for Elementor: Cross-site scripting
PowerPack Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 30, 2024 CVE-2024-2491
PowerPack Addons for Elementor: Cross-site scripting
PowerPack Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 29, 2024 CVE-2024-1411
PowerPack Addons for Elementor: Cross-site scripting
PowerPack Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 03, 2024 CVE-2023-6984
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates): Cross-site request forgery
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.3
NVD4.3
Jan 03, 2022 CVE-2021-25027
PowerPack Addons for Elementor: Cross-site scripting
PowerPack Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
May 05, 2021 CVE-2021-24263
“Elementor Addons – PowerPack Addons for Elementor”: Cross-site scripting
“Elementor Addons – PowerPack Addons for Elementor” is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4