plugin

Piotnet Addons For Elementor Vulnerabilities

21 known security issues reported for the Piotnet Addons For Elementor WordPress plugin. Most recent disclosed Apr 18, 2025.

10 medium

Running Piotnet Addons For Elementor on your site? Check whether your installed version is affected.

Scan your site free

Piotnet Addons For Elementor [piotnet-addons-for-elementor] <= 2.4.34 (unfixed)

unknown

[en] The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before After Image Comparison Slider' widget in all versions up to, and including, 2.4.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

Affected:
up to 2.4.34
Fix:
No patched version reported
Disclosed:
Apr 18, 2025

CVE-2024-13650 on NVD →

Piotnet Addons For Elementor <= 2.4.36 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before After Image Comparison Slider' widget in all versions up to, and including, 2.4.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 2.4.36
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2024-13650 on NVD →

Piotnet Addons For Elementor <= 2.4.36 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr...

CVSS:
6.4
Affected:
up to 2.4.36
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32197 on NVD →

Piotnet Addons For Elementor [piotnet-addons-for-elementor] <= 2.4.36 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Addons For Elementor allows Stored XSS. This issue affects Piotnet Addons For Elementor: from n/a through 2.4.34.

Affected:
up to 2.4.36
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32197 on NVD →

Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.33

unknown

[en] The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.4.32 via the 'pafe-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level acce...

Affected:
up to 2.4.33
Fixed in:
2.4.33
Disclosed:
Jan 15, 2025

CVE-2024-10775 on NVD →

Piotnet Addons For Elementor <= 2.4.32 - Authenticated (Contributor+) Post Disclosure

medium

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.4.32 via the 'pafe-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access an...

CVSS:
4.3
Affected:
up to 2.4.32
Fixed in:
2.4.33
Disclosed:
Jan 14, 2025

CVE-2024-10775 on NVD →

Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.32

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.31.

Affected:
up to 2.4.32
Fixed in:
2.4.32
Disclosed:
Jan 7, 2025

CVE-2025-22333 on NVD →

Piotnet Addons For Elementor <= 2.4.31 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Heading widget in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 2.4.31
Fixed in:
2.4.32
Disclosed:
Jan 3, 2025

CVE-2025-22333 on NVD →

Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.31

unknown

[en] The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion, Dual Heading, and Vertical Timeline widgets in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping on user supplied attributes. This...

Affected:
up to 2.4.31
Fixed in:
2.4.31
Disclosed:
Aug 23, 2024

CVE-2024-5502 on NVD →

Piotnet Addons For Elementor <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

medium

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion, Dual Heading, and Vertical Timeline widgets in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...

CVSS:
6.4
Affected:
up to 2.4.30
Fixed in:
2.4.31
Disclosed:
Aug 22, 2024

CVE-2024-5502 on NVD →

Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.30

unknown

[en] The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.29 via the 'pafe_posts_list' function. This makes it possible for unauthenticated attackers to extract sensitive data including titles and excerpts of future, draft, and p...

Affected:
up to 2.4.30
Fixed in:
2.4.30
Disclosed:
Jul 27, 2024

CVE-2024-5614 on NVD →

Piotnet Addons For Elementor <= 2.4.29 - Unauthenticated Sensitive Information Exposure

medium

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.29 via the 'pafe_posts_list' function. This makes it possible for unauthenticated attackers to extract sensitive data including titles and excerpts of future, draft, and pendin...

CVSS:
5.3
Affected:
up to 2.4.29
Fixed in:
2.4.30
Disclosed:
Jul 26, 2024

CVE-2024-5614 on NVD →

Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.29

unknown

[en] The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.4.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...

Affected:
up to 2.4.29
Fixed in:
2.4.29
Disclosed:
May 22, 2024

CVE-2024-4262 on NVD →

Piotnet Addons For Elementor <= 2.4.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widget Attributes

medium

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.4.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributo...

CVSS:
6.4
Affected:
up to 2.4.28
Fixed in:
2.4.29
Disclosed:
May 21, 2024

CVE-2024-4262 on NVD →

Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.28

unknown

[en] The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.4.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with c...

Affected:
up to 2.4.28
Fixed in:
2.4.28
Disclosed:
May 18, 2024

CVE-2024-4432 on NVD →

Piotnet Addons For Elementor <= 2.4.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

medium

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.4.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri...

CVSS:
6.4
Affected:
up to 2.4.26
Fixed in:
2.4.28
Disclosed:
May 17, 2024

CVE-2024-4432 on NVD →

Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.27

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.26.

Affected:
up to 2.4.27
Fixed in:
2.4.27
Disclosed:
Apr 29, 2024

CVE-2024-33630 on NVD →

Piotnet Addons For Elementor <= 2.4.27 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr...

CVSS:
6.4
Affected:
up to 2.4.27
Fixed in:
2.4.28
Disclosed:
Apr 25, 2024

CVE-2024-33630 on NVD →

Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.26

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.25.

Affected:
up to 2.4.26
Fixed in:
2.4.26
Disclosed:
Mar 27, 2024

CVE-2024-29934 on NVD →

Piotnet Addons For Elementor <= 2.4.25 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr...

CVSS:
6.4
Affected:
up to 2.4.25
Fixed in:
2.4.26
Disclosed:
Mar 25, 2024

CVE-2024-29934 on NVD →

Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.32

unknown
Affected:
up to 2.4.32
Fixed in:
2.4.32

CVE-2024-9673 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database