Rife Elementor Extensions & Templates [rife-elementor-extensions] < 1.2.6
unknown
[en] The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f...
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Feb 22, 2025
CVE-2024-13564 on NVD →
Rife Elementor Extensions & Templates <= 1.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Writing Effect Headline Shortcode
medium
The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...
- CVSS:
- 6.4
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.6
- Disclosed:
- Feb 21, 2025
CVE-2024-13564 on NVD →
Rife Elementor Extensions & Templates [rife-elementor-extensions] < 1.2.0
unknown
[en] Missing Authorization vulnerability in Apollo13Themes Rife Elementor Extensions & Templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rife Elementor Extensions & Templates: from n/a through 1.1.10.
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
- Disclosed:
- Dec 9, 2024
CVE-2023-27454 on NVD →
Rife Elementor Extensions & Templates [rife-elementor-extensions] < 1.2.2
unknown
[en] The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute within the plugin's Writing Effect Headline widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes....
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Jul 2, 2024
CVE-2024-5504 on NVD →
Rife Elementor Extensions & Templates <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Writing Effect Headline Widget
medium
The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute within the plugin's Writing Effect Headline widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This...
- CVSS:
- 6.4
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- Jul 1, 2024
CVE-2024-5504 on NVD →
Rife Elementor Extensions & Templates <= 1.1.10 - Missing Authorization via import_templates
medium
The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'import_templates' function in versions up to, and including, 1.1.10. This makes it possible for authenticated attackers with subscriber-level access, and above, to import and...
- CVSS:
- 5.4
- Affected:
- up to 1.1.10
- Fixed in:
- 1.2.0
- Disclosed:
- Mar 2, 2023
CVE-2023-27454 on NVD →
Rife Elementor Extensions & Templates [rife-elementor-extensions] < 1.1.6
unknown
[en] The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method.
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- May 5, 2021
CVE-2021-24265 on NVD →
Rife Elementor Extensions & Templates <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method.
- CVSS:
- 6.4
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- Apr 13, 2021
CVE-2021-24265 on NVD →
Rife Elementor Extensions & Templates [rife-elementor-extensions] < 1.1.6
unknown
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress Rife Elementor Extensions & Templates plugin (versions <= 1.1.5).
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- Apr 13, 2021
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database