PowerPack Pro for Elementor < v2.13.0 - Missing Authorization
medium
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to v2.13.0 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to v2.13.0
- Fixed in:
- 2.13.0
- Disclosed:
- Apr 29, 2026
CVE-2026-42629 on NVD →
PowerPack Addons for Elementor [powerpack-elements] < 2.10.15
unknown
[en] Improper Privilege Management vulnerability in IdeaBox PowerPack Pro for Elementor allows Privilege Escalation.This issue affects PowerPack Pro for Elementor: from n/a through 2.10.14.
- Affected:
- up to 2.10.15
- Fixed in:
- 2.10.15
- Disclosed:
- Aug 1, 2024
CVE-2024-39634 on NVD →
PowerPack Pro for Elementor <= 2.10.14 - Authenticated (Contributor+) Privilege Escalation
high
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.10.14. This is due to plugin not properly restricting who can set roles on the user registration form. This makes it possible for unauthenticated attackers to create user accounts that have...
- CVSS:
- 8.8
- Affected:
- up to 2.10.14
- Fixed in:
- 2.10.15
- Disclosed:
- Jul 24, 2024
CVE-2024-39634 on NVD →
PowerPack Addons for Elementor [powerpack-elements] < 2.10.18
unknown
[en] The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible for authenticated attackers, with cont...
- Affected:
- up to 2.10.18
- Fixed in:
- 2.10.18
- Disclosed:
- Jun 8, 2024
CVE-2024-3668 on NVD →
PowerPack Pro for Elementor <= 2.10.17 - Authenticated (Contributor+) Privilege Escalation
high
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible for authenticated attackers, with contribut...
- CVSS:
- 8.8
- Affected:
- up to 2.10.17
- Fixed in:
- 2.10.18
- Disclosed:
- Jun 7, 2024
CVE-2024-3668 on NVD →
PowerPack Addons for Elementor [powerpack-elements] < 2.10.8
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Addons for Elementor PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a before 2.10.8.
- Affected:
- up to 2.10.8
- Fixed in:
- 2.10.8
- Disclosed:
- Feb 21, 2024
CVE-2024-24843 on NVD →
PowerPack Pro for Elementor <= 2.10.6 - Missing Authorization to Settings Reset
high
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in all versions up to, and including, 2.10.6. This makes it possible for unauthenticated attackers to reset plugin settings.
- CVSS:
- 7.5
- Affected:
- up to 2.10.6
- Fixed in:
- 2.10.8
- Disclosed:
- Feb 2, 2024
CVE-2024-24844 on NVD →
PowerPack Pro for Elementor < 2.10.8 - Cross-Site Request Forgery to Plugin Settings Modification and Cross-Site Scripting
medium
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions prior to 2.10.8. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to modify plugin settings and inject arbitrary web scripts in pages via a forged reques...
- CVSS:
- 6.1
- Affected:
- up to 2.10.8
- Fixed in:
- 2.10.8
- Disclosed:
- Feb 2, 2024
CVE-2024-24843 on NVD →
PowerPack Addons for Elementor [powerpack-elements] < 2.10.8
unknown
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in all versions up to, and including, 2.10.6. This makes it possible for unauthenticated attackers to reset plugin settings.
- Affected:
- up to 2.10.8
- Fixed in:
- 2.10.8
- Disclosed:
- Feb 2, 2024
PowerPack Addons for Elementor [powerpack-elements] < 2.9.24
unknown
[en] Vulnerability in IdeaBox Creations PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a through 2.9.23.
- Affected:
- up to 2.9.24
- Fixed in:
- 2.9.24
- Disclosed:
- Dec 14, 2023
CVE-2023-49739 on NVD →
PowerPack Pro for Elementor <= 2.9.23 - Reflected Cross-Site Scripting
medium
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 6.1
- Affected:
- up to 2.9.23
- Fixed in:
- 2.9.24
- Disclosed:
- Dec 1, 2023
CVE-2023-49739 on NVD →
PowerPack Addons for Elementor [powerpack-elements] < 2.10.8
unknown
- Affected:
- up to 2.10.8
- Fixed in:
- 2.10.8
CVE-2024-24844 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database