plugin

Envo Elementor For Woocommerce Vulnerabilities

7 known security issues reported for the Envo Elementor For Woocommerce WordPress plugin. Most recent disclosed Jul 1, 2026.

7 medium

Running Envo Elementor For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting

medium

The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's template rendering in versions up to, and including, 1.4.26. The render() method of the Tabs widget passes a user...

CVSS:
4.3
Affected:
up to 1.4.26
Fixed in:
1.4.27
Disclosed:
Jul 1, 2026

CVE-2026-11600 on NVD →

Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.19 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to...

CVSS:
6.4
Affected:
up to 1.4.19
Fixed in:
1.4.20
Disclosed:
Oct 24, 2024

CVE-2024-50447 on NVD →

Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.16 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to injec...

CVSS:
6.4
Affected:
up to 1.4.16
Fixed in:
1.4.17
Disclosed:
Aug 16, 2024

CVE-2024-43292 on NVD →

Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to i...

CVSS:
6.4
Affected:
up to 1.4.8
Fixed in:
1.4.9
Disclosed:
May 10, 2024

CVE-2024-35167 on NVD →

Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.4 - Cross-Site Request Forgery via ajax_theme_activation

medium

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4.4. This is due to missing or incorrect nonce validation on the ajax_theme_activation function. This makes it possible for unauthenticated attackers to activate ar...

CVSS:
4.3
Affected:
up to 1.4.4
Fixed in:
1.4.5
Disclosed:
Feb 27, 2024

CVE-2024-0768 on NVD →

Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.4 - Missing Authorization via templates_ajax_request

medium

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the templates_ajax_request function in all versions up to, and including, 1.4.4. This makes it possible for subscribers and higher to create templates.

CVSS:
4.3
Affected:
up to 1.4.4
Fixed in:
1.4.5
Disclosed:
Feb 27, 2024

CVE-2024-0766 on NVD →

Envo's Elementor Templates & Widgets for WooCommerce <= 1.4.4 - Cross-Site Request Forgery via ajax_plugin_activation

medium

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation on the ajax_plugin_activation function. This makes it possible for unauthenticated attackers to activate...

CVSS:
4.3
Affected:
up to 1.4.4
Fixed in:
1.4.5
Disclosed:
Feb 27, 2024

CVE-2024-0767 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database