← WordPress Vulnerabilities
WordPress security by component

PowerPack Addons for Elementor

PowerPack Addons for Elementor (powerpack-addons-for-elementor) is a WordPress plugin with 7 published CVE records in this archive. The latest tracked vulnerability was published Jun 08, 2024; the highest published CVSS base score is 8.8.

Plugin slug: powerpack-addons-for-elementor

CVE-2024-3668: PowerPack Pro for Elementor: Privilege escalation or authentication bypass

PowerPack Pro for Elementor is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated contributor account. A successful request can grant permissions or access that the caller should not possess.

PublishedJun 08, 2024
Safe version guidanceSee mitigation notes
Published vulnerabilities for powerpack-addons-for-elementor
Safe version
Jun 08, 2024 CVE-2024-3668
PowerPack Pro for Elementor: Privilege escalation or authentication bypass
PowerPack Pro for Elementor is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated contributor account. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Apr 09, 2024 CVE-2024-2492
PowerPack Addons for Elementor: Cross-site scripting
PowerPack Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 30, 2024 CVE-2024-2491
PowerPack Addons for Elementor: Cross-site scripting
PowerPack Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 29, 2024 CVE-2024-1411
PowerPack Addons for Elementor: Cross-site scripting
PowerPack Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 03, 2024 CVE-2023-6984
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates): Cross-site request forgery
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.3
NVD4.3
Jan 03, 2022 CVE-2021-25027
PowerPack Addons for Elementor: Cross-site scripting
PowerPack Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
May 05, 2021 CVE-2021-24263
“Elementor Addons – PowerPack Addons for Elementor”: Cross-site scripting
“Elementor Addons – PowerPack Addons for Elementor” is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4