← WordPress Vulnerabilities
WordPress security by component

Startklar Elementor Addons

Startklar Elementor Addons is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jun 06, 2024; the highest CVE/CNA score is 9.8.

Plugin slug: startklar-elmentor-forms-extwidgets

CVE-2024-5153: Startklar Elementor Addons: Filesystem traversal

Startklar Elementor Addons is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.

PublishedJun 06, 2024
Safe version guidanceSee mitigation notes
Safe version
Jun 06, 2024 CVE-2024-5153
Startklar Elementor Addons: Filesystem traversal
Startklar Elementor Addons is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE9.1
NVD9.8
May 07, 2024 CVE-2024-4346
Startklar Elementor Addons: Code execution
Startklar Elementor Addons is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.1
NVDPending
May 07, 2024 CVE-2024-4345
Startklar Elementor Addons: Dangerous file upload
Startklar Elementor Addons is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.8
NVDPending