CVE-2021-24351 – The Plus Addons for Elementor < 4.1.12 - Reflected Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2021-24351
31 May 2021 — The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scripting (exploitable on both unauthenticated and authenticated users) La acción AJAX theplus_more_post del plugin Plus Addons para Elementor Page Builder WordPress versiones anteriores a 4.1.12, no saneaba apropiadamente algunos de sus campos, conllevando a una vulnerabilidad de tipo Cross-Site Scripting reflejado (ex... • https://theplusaddons.com/changelog • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-4332 – The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read
https://notcve.org/view.php?id=CVE-2021-4332
14 Apr 2021 — The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box. Unfortunately, the plugin used file_get_contents with no verification that the file being supplied was an SVG file, so any user with access to the Elementor page builder, such as contributors, could read arbitrary files on the WordP... • https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2523506%40the-plus-addons-for-elementor-page-builder&new=2523506%40the-plus-addons-for-elementor-page-builder&sfp_email=&sfph_mail= • CWE-73: External Control of File Name or Path •
CVE-2021-4331 – The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege Escalation
https://notcve.org/view.php?id=CVE-2021-4331
14 Apr 2021 — The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registration form to the Elementor page builders functionality. As part of the registration form, users can choose which role to set as the default for users upon registration. This field is not hidden for lower-level users so any user with access to the Elementor page builder, such as contributors, can set the default role to administrator... • https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2514618%40the-plus-addons-for-elementor-page-builder&new=2514618%40the-plus-addons-for-elementor-page-builder&sfp_email=&sfph_mail= • CWE-862: Missing Authorization •
CVE-2021-24266 – The Plus Addons for Elementor Page Builder Lite < 2.0.6 - Contributor+ Stored XSS
https://notcve.org/view.php?id=CVE-2021-24266
13 Apr 2021 — The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. El Plugin de WordPress "The Plus Addons for Elementor Page Builder Lite" versiones anteriores a 2.0.6, presenta cuatro widgets que son vulnerables a un ataque de tipo Cross-Site Scripting (XSS) almacenado por usuarios cpn menos privilegios, como los contribuyentes, todo por medio... • https://wpscan.com/vulnerability/78014ddd-1cc2-4723-8194-4bf478888578 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-24175 – The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
https://notcve.org/view.php?id=CVE-2021-24175
08 Mar 2021 — The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active. El plugin de WordPress Plus Addons for Elementor Page Builder versiones anteriores a 4... • https://posimyth.ticksy.com/ticket/2713734 • CWE-287: Improper Authentication •