ElementsReady Addons for Elementor <= 6.6.2 - Cross-Site Request Forgery
medium
The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.6.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can...
- CVSS:
- 4.3
- Affected:
- up to 6.6.2
- Fixed in:
- 6.6.3
- Disclosed:
- Apr 16, 2025
CVE-2025-39546 on NVD →
ElementsReady Addons for Elementor [element-ready-lite] < 6.6.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in quomodosoft ElementsReady Addons for Elementor allows Cross Site Request Forgery. This issue affects ElementsReady Addons for Elementor: from n/a through 6.6.2.
- Affected:
- up to 6.6.3
- Fixed in:
- 6.6.3
- Disclosed:
- Apr 16, 2025
CVE-2025-39546 on NVD →
ElementsReady Addons for Elementor [element-ready-lite] < 6.4.9
unknown
[en] The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.8 in inc/Widgets/accordion/output/content.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive priv...
- Affected:
- up to 6.4.9
- Fixed in:
- 6.4.9
- Disclosed:
- Dec 17, 2024
CVE-2024-10356 on NVD →
ElementsReady Addons for Elementor <= 6.4.8 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates
medium
The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.8 in inc/Widgets/accordion/output/content.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private,...
- CVSS:
- 4.3
- Affected:
- up to 6.4.8
- Fixed in:
- 6.4.9
- Disclosed:
- Dec 16, 2024
CVE-2024-10356 on NVD →
ElementsReady Addons for Elementor [element-ready-lite] < 6.4.8
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows DOM-Based XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 6.4.7.
- Affected:
- up to 6.4.8
- Fixed in:
- 6.4.8
- Disclosed:
- Dec 9, 2024
CVE-2024-54224 on NVD →
ElementsReady Addons for Elementor <= 6.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...
- CVSS:
- 6.4
- Affected:
- up to 6.4.7
- Fixed in:
- 6.4.8
- Disclosed:
- Dec 5, 2024
CVE-2024-54224 on NVD →
ElementsReady Addons for Elementor [element-ready-lite] < 6.4.4
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows Stored XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 6.4.3.
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.4
- Disclosed:
- Nov 9, 2024
CVE-2024-51787 on NVD →
ElementsReady Addons for Elementor <= 6.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...
- CVSS:
- 6.4
- Affected:
- up to 6.4.3
- Fixed in:
- 6.4.4
- Disclosed:
- Nov 4, 2024
CVE-2024-51787 on NVD →
ElementsReady Addons for Elementor [element-ready-lite] < 6.4.4
unknown
[en] The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and abov...
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.4
- Disclosed:
- Oct 16, 2024
CVE-2024-9444 on NVD →
ElementsReady Addons for Elementor <= 6.4.3 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
medium
The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to...
- CVSS:
- 6.4
- Affected:
- up to 6.4.3
- Fixed in:
- 6.4.4
- Disclosed:
- Oct 15, 2024
CVE-2024-9444 on NVD →
ElementsReady Addons for Elementor [element-ready-lite] < 6.4.3
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in QuomodoSoft ElementsReady Addons for Elementor.This issue affects ElementsReady Addons for Elementor: from n/a through 6.4.2.
- Affected:
- up to 6.4.3
- Fixed in:
- 6.4.3
- Disclosed:
- Oct 11, 2024
CVE-2024-47353 on NVD →
ElementsReady Addons for Elementor [element-ready-lite] < 6.4.1
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows Stored XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 6.4.0.
- Affected:
- up to 6.4.1
- Fixed in:
- 6.4.1
- Disclosed:
- Oct 6, 2024
CVE-2024-47329 on NVD →
ElementsReady Addons for Elementor 6.4.2 - Open Redirect
medium
The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Open Redirect in version 6.4.2. This is due to insufficient validation on a redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into p...
- CVSS:
- 6.1
- Affected:
- 6.4.2 – 6.4.2
- Fixed in:
- 6.4.3
- Disclosed:
- Sep 30, 2024
CVE-2024-47353 on NVD →
ElementsReady Addons for Elementor <= 6.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...
- CVSS:
- 6.4
- Affected:
- up to 6.4.0
- Fixed in:
- 6.4.1
- Disclosed:
- Sep 25, 2024
CVE-2024-47329 on NVD →
ElementsReady Addons for Elementor [element-ready-lite] < 6.2.0
unknown
[en] The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 6.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access...
- Affected:
- up to 6.2.0
- Fixed in:
- 6.2.0
- Disclosed:
- Jun 6, 2024
CVE-2024-5152 on NVD →
ElementsReady Addons for Elementor <= 6.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 6.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and a...
- CVSS:
- 6.4
- Affected:
- up to 6.1.0
- Fixed in:
- 6.2.0
- Disclosed:
- Jun 5, 2024
CVE-2024-5152 on NVD →
ElementsReady Addons for Elementor [element-ready-lite] < 5.9.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows Stored XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 5.8.0.
- Affected:
- up to 5.9.0
- Fixed in:
- 5.9.0
- Disclosed:
- May 6, 2024
CVE-2024-34374 on NVD →
ElementsReady Addons for Elementor <= 5.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...
- CVSS:
- 6.4
- Affected:
- up to 5.8.0
- Fixed in:
- 5.9.0
- Disclosed:
- May 3, 2024
CVE-2024-34374 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database