plugin

Rife Elementor Extensions Vulnerabilities

9 known security issues reported for the Rife Elementor Extensions WordPress plugin. Most recent disclosed Feb 22, 2025.

4 medium

Running Rife Elementor Extensions on your site? Check whether your installed version is affected.

Scan your site free

Rife Elementor Extensions &amp; Templates [rife-elementor-extensions] < 1.2.6

unknown

[en] The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f...

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Feb 22, 2025

CVE-2024-13564 on NVD →

Rife Elementor Extensions & Templates <= 1.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Writing Effect Headline Shortcode

medium

The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...

CVSS:
6.4
Affected:
up to 1.2.5
Fixed in:
1.2.6
Disclosed:
Feb 21, 2025

CVE-2024-13564 on NVD →

Rife Elementor Extensions &amp; Templates [rife-elementor-extensions] < 1.2.0

unknown

[en] Missing Authorization vulnerability in Apollo13Themes Rife Elementor Extensions & Templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rife Elementor Extensions & Templates: from n/a through 1.1.10.

Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Dec 9, 2024

CVE-2023-27454 on NVD →

Rife Elementor Extensions &amp; Templates [rife-elementor-extensions] < 1.2.2

unknown

[en] The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute within the plugin's Writing Effect Headline widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes....

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Jul 2, 2024

CVE-2024-5504 on NVD →

Rife Elementor Extensions & Templates <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Writing Effect Headline Widget

medium

The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute within the plugin's Writing Effect Headline widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This...

CVSS:
6.4
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Jul 1, 2024

CVE-2024-5504 on NVD →

Rife Elementor Extensions & Templates <= 1.1.10 - Missing Authorization via import_templates

medium

The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'import_templates' function in versions up to, and including, 1.1.10. This makes it possible for authenticated attackers with subscriber-level access, and above, to import and...

CVSS:
5.4
Affected:
up to 1.1.10
Fixed in:
1.2.0
Disclosed:
Mar 2, 2023

CVE-2023-27454 on NVD →

Rife Elementor Extensions &amp; Templates [rife-elementor-extensions] < 1.1.6

unknown

[en] The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method.

Affected:
up to 1.1.6
Fixed in:
1.1.6
Disclosed:
May 5, 2021

CVE-2021-24265 on NVD →

Rife Elementor Extensions & Templates <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method.

CVSS:
6.4
Affected:
up to 1.1.6
Fixed in:
1.1.6
Disclosed:
Apr 13, 2021

CVE-2021-24265 on NVD →

Rife Elementor Extensions &amp; Templates [rife-elementor-extensions] < 1.1.6

unknown

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress Rife Elementor Extensions & Templates plugin (versions <= 1.1.5).

Affected:
up to 1.1.6
Fixed in:
1.1.6
Disclosed:
Apr 13, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database