Borderless – Elementor Addons and Templates <= 1.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Borderless – Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level a...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- May 30, 2025
CVE-2025-5290 on NVD →
Borderless – Elementor Addons and Templates [borderless] < 1.6.3
unknown
[en] The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- Jan 31, 2025
CVE-2024-10867 on NVD →
Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.6.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload
medium
The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...
- CVSS:
- 5.4
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.3
- Disclosed:
- Jan 30, 2025
CVE-2024-10867 on NVD →
Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.6.0 - Authenticated (Administrator+) Remote Code Execution
high
The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.6.0 via the 'write_config' function. This is due to a lack of sanitization on an imported JSON file. This makes it possible for authenti...
- CVSS:
- 7.2
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.1
- Disclosed:
- Jan 30, 2025
CVE-2024-11600 on NVD →
Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.5.9 - Missing Authorization to Icon Font Deletion
medium
The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_zipped_font' function in all versions up to, and including, 1.5.9. This makes it possible for authenticated attackers, with...
- CVSS:
- 4.3
- Affected:
- up to 1.5.9
- Fixed in:
- 1.6.0
- Disclosed:
- Jan 30, 2025
CVE-2024-11583 on NVD →
Borderless – Elementor Addons and Templates [borderless] < 1.6.1
unknown
[en] The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.9 via the 'write_config' function. This is due to a lack of sanitization on an imported JSON file. This makes it possible for aut...
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Jan 30, 2025
CVE-2024-11600 on NVD →
Borderless – Elementor Addons and Templates [borderless] < 1.6.0
unknown
[en] The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_zipped_font' function in all versions up to, and including, 1.5.9. This makes it possible for authenticated attackers,...
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
- Disclosed:
- Jan 30, 2025
CVE-2024-11583 on NVD →
Borderless – Elementor Addons and Templates [borderless] < 1.5.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderless allows Cross-Site Scripting (XSS).This issue affects Borderless: from n/a through 1.5.8.
- Affected:
- up to 1.5.9
- Fixed in:
- 1.5.9
- Disclosed:
- Dec 6, 2024
CVE-2024-54211 on NVD →
Borderless <= 1.5.8 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Borderless plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will...
- CVSS:
- 5.5
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.9
- Disclosed:
- Dec 2, 2024
CVE-2024-54211 on NVD →
Borderless – Elementor Addons and Templates [borderless] < 1.5.4
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Visualmodo Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg allows Stored XSS.This issue affects Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenber...
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.4
- Disclosed:
- May 17, 2024
CVE-2024-34757 on NVD →
Borderless - Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos...
- CVSS:
- 6.4
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.4
- Disclosed:
- May 14, 2024
CVE-2024-4666 on NVD →
Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget attributes in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacke...
- CVSS:
- 6.4
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.4
- Disclosed:
- May 14, 2024
CVE-2024-34757 on NVD →
Borderless – Elementor Addons and Templates [borderless] < 1.5.4
unknown
[en] The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i...
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.4
- Disclosed:
- May 14, 2024
CVE-2024-4666 on NVD →
Borderless – Elementor Addons and Templates [borderless] < 1.4.9
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Visualmodo Borderless plugin <= 1.4.8 versions.
- Affected:
- up to 1.4.9
- Fixed in:
- 1.4.9
- Disclosed:
- Sep 3, 2023
CVE-2023-38518 on NVD →
Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.4.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator...
- CVSS:
- 4.4
- Affected:
- up to 1.4.8
- Fixed in:
- 1.4.9
- Disclosed:
- Jul 20, 2023
CVE-2023-38518 on NVD →
Borderless – Elementor Addons and Templates [borderless] < 1.7.2
unknown
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
CVE-2025-5290 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database