Piotnet Addons For Elementor [piotnet-addons-for-elementor] <= 2.4.34 (unfixed)
unknown
[en] The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before After Image Comparison Slider' widget in all versions up to, and including, 2.4.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- Affected:
- up to 2.4.34
- Fix:
- No patched version reported
- Disclosed:
- Apr 18, 2025
CVE-2024-13650 on NVD →
Piotnet Addons For Elementor <= 2.4.36 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before After Image Comparison Slider' widget in all versions up to, and including, 2.4.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 2.4.36
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2025
CVE-2024-13650 on NVD →
Piotnet Addons For Elementor <= 2.4.36 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 2.4.36
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-32197 on NVD →
Piotnet Addons For Elementor [piotnet-addons-for-elementor] <= 2.4.36 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Addons For Elementor allows Stored XSS. This issue affects Piotnet Addons For Elementor: from n/a through 2.4.34.
- Affected:
- up to 2.4.36
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-32197 on NVD →
Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.33
unknown
[en] The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.4.32 via the 'pafe-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level acce...
- Affected:
- up to 2.4.33
- Fixed in:
- 2.4.33
- Disclosed:
- Jan 15, 2025
CVE-2024-10775 on NVD →
Piotnet Addons For Elementor <= 2.4.32 - Authenticated (Contributor+) Post Disclosure
medium
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.4.32 via the 'pafe-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access an...
- CVSS:
- 4.3
- Affected:
- up to 2.4.32
- Fixed in:
- 2.4.33
- Disclosed:
- Jan 14, 2025
CVE-2024-10775 on NVD →
Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.32
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.31.
- Affected:
- up to 2.4.32
- Fixed in:
- 2.4.32
- Disclosed:
- Jan 7, 2025
CVE-2025-22333 on NVD →
Piotnet Addons For Elementor <= 2.4.31 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Heading widget in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 2.4.31
- Fixed in:
- 2.4.32
- Disclosed:
- Jan 3, 2025
CVE-2025-22333 on NVD →
Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.31
unknown
[en] The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion, Dual Heading, and Vertical Timeline widgets in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping on user supplied attributes. This...
- Affected:
- up to 2.4.31
- Fixed in:
- 2.4.31
- Disclosed:
- Aug 23, 2024
CVE-2024-5502 on NVD →
Piotnet Addons For Elementor <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion, Dual Heading, and Vertical Timeline widgets in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...
- CVSS:
- 6.4
- Affected:
- up to 2.4.30
- Fixed in:
- 2.4.31
- Disclosed:
- Aug 22, 2024
CVE-2024-5502 on NVD →
Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.30
unknown
[en] The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.29 via the 'pafe_posts_list' function. This makes it possible for unauthenticated attackers to extract sensitive data including titles and excerpts of future, draft, and p...
- Affected:
- up to 2.4.30
- Fixed in:
- 2.4.30
- Disclosed:
- Jul 27, 2024
CVE-2024-5614 on NVD →
Piotnet Addons For Elementor <= 2.4.29 - Unauthenticated Sensitive Information Exposure
medium
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.29 via the 'pafe_posts_list' function. This makes it possible for unauthenticated attackers to extract sensitive data including titles and excerpts of future, draft, and pendin...
- CVSS:
- 5.3
- Affected:
- up to 2.4.29
- Fixed in:
- 2.4.30
- Disclosed:
- Jul 26, 2024
CVE-2024-5614 on NVD →
Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.29
unknown
[en] The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.4.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...
- Affected:
- up to 2.4.29
- Fixed in:
- 2.4.29
- Disclosed:
- May 22, 2024
CVE-2024-4262 on NVD →
Piotnet Addons For Elementor <= 2.4.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widget Attributes
medium
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.4.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributo...
- CVSS:
- 6.4
- Affected:
- up to 2.4.28
- Fixed in:
- 2.4.29
- Disclosed:
- May 21, 2024
CVE-2024-4262 on NVD →
Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.28
unknown
[en] The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.4.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with c...
- Affected:
- up to 2.4.28
- Fixed in:
- 2.4.28
- Disclosed:
- May 18, 2024
CVE-2024-4432 on NVD →
Piotnet Addons For Elementor <= 2.4.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.4.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri...
- CVSS:
- 6.4
- Affected:
- up to 2.4.26
- Fixed in:
- 2.4.28
- Disclosed:
- May 17, 2024
CVE-2024-4432 on NVD →
Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.27
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.26.
- Affected:
- up to 2.4.27
- Fixed in:
- 2.4.27
- Disclosed:
- Apr 29, 2024
CVE-2024-33630 on NVD →
Piotnet Addons For Elementor <= 2.4.27 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 2.4.27
- Fixed in:
- 2.4.28
- Disclosed:
- Apr 25, 2024
CVE-2024-33630 on NVD →
Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.26
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.25.
- Affected:
- up to 2.4.26
- Fixed in:
- 2.4.26
- Disclosed:
- Mar 27, 2024
CVE-2024-29934 on NVD →
Piotnet Addons For Elementor <= 2.4.25 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 2.4.25
- Fixed in:
- 2.4.26
- Disclosed:
- Mar 25, 2024
CVE-2024-29934 on NVD →
Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.32
unknown
- Affected:
- up to 2.4.32
- Fixed in:
- 2.4.32
CVE-2024-9673 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database