themesflat-addons-for-elementor <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The themesflat-addons-for-elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...
- CVSS:
- 6.4
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Mar 23, 2026
CVE-2026-39500 on NVD →
Themesflat Addons For Elementor <= 2.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider widget in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and a...
- CVSS:
- 6.4
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.6
- Disclosed:
- Apr 18, 2025
CVE-2025-3275 on NVD →
Themesflat Addons For Elementor <= 2.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...
- CVSS:
- 6.4
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Mar 31, 2025
CVE-2025-31567 on NVD →
Themesflat Addons For Elementor [themesflat-addons-for-elementor] <= 2.2.6 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows Stored XSS. This issue affects Themesflat Addons For Elementor: from n/a through 2.2.5.
- Affected:
- up to 2.2.6
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2025
CVE-2025-31567 on NVD →
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.5
unknown
[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access...
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Jan 8, 2025
CVE-2024-12205 on NVD →
Themesflat Addons For Elementor <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and a...
- CVSS:
- 6.4
- Affected:
- up to 2.2.4
- Fixed in:
- 2.2.5
- Disclosed:
- Jan 7, 2025
CVE-2024-12205 on NVD →
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows DOM-Based XSS.This issue affects Themesflat Addons For Elementor: from n/a through 2.2.2.
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
- Disclosed:
- Dec 6, 2024
CVE-2024-53796 on NVD →
Themesflat Addons For Elementor <= 2.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...
- CVSS:
- 6.4
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.3
- Disclosed:
- Dec 2, 2024
CVE-2024-53796 on NVD →
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.2
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows Stored XSS.This issue affects Themesflat Addons For Elementor: from n/a through 2.2.0.
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.2
- Disclosed:
- Oct 17, 2024
CVE-2024-49310 on NVD →
Themesflat Addons For Elementor <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...
- CVSS:
- 6.4
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Oct 15, 2024
CVE-2024-49310 on NVD →
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.2
unknown
[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract limited post information from draft and futur...
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.2
- Disclosed:
- Sep 25, 2024
CVE-2024-8516 on NVD →
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.2
unknown
[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on URL attributes....
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.2
- Disclosed:
- Sep 25, 2024
CVE-2024-8515 on NVD →
Themesflat Addons For Elementor <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on URL attributes. This...
- CVSS:
- 6.4
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Sep 24, 2024
CVE-2024-8515 on NVD →
Themesflat Addons For Elementor <= 2.2.1 - Authenticated (Contributor+) Information Exposure
medium
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract limited post information from draft and future sch...
- CVSS:
- 4.3
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Sep 24, 2024
CVE-2024-8516 on NVD →
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3
unknown
[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget tags in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Jun 6, 2024
CVE-2024-2922 on NVD →
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3
unknown
[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget's titles in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke...
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Jun 6, 2024
CVE-2024-4459 on NVD →
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3
unknown
[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TF Group Image, TF Nav Menu, TF Posts, TF Woo Product Grid, TF Accordion, and TF Image Box widgets in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output esc...
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Jun 6, 2024
CVE-2024-4212 on NVD →
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3
unknown
[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets via URL parameters in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor ac...
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Jun 6, 2024
CVE-2024-4458 on NVD →
Themesflat Addons For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Tags
medium
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget tags in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.3
- Disclosed:
- Jun 5, 2024
CVE-2024-2922 on NVD →
Themesflat Addons For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via URLs
medium
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets via URL parameters in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access...
- CVSS:
- 6.4
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.3
- Disclosed:
- Jun 5, 2024
CVE-2024-4458 on NVD →
Themesflat Addons For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting in Multiple Widgets
medium
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TF Group Image, TF Nav Menu, TF Posts, TF Woo Product Grid, TF Accordion, and TF Image Box widgets in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping...
- CVSS:
- 6.4
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.3
- Disclosed:
- Jun 5, 2024
CVE-2024-4212 on NVD →
Themesflat Addons For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Titles
medium
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget's titles in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...
- CVSS:
- 6.4
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.3
- Disclosed:
- Jun 5, 2024
CVE-2024-4459 on NVD →
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows Stored XSS.This issue affects Themesflat Addons For Elementor: from n/a through 2.1.2.
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Jun 4, 2024
CVE-2024-35666 on NVD →
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.0.1
unknown
[en] Deserialization of Untrusted Data vulnerability in Themesflat Themesflat Addons For Elementor.This issue affects Themesflat Addons For Elementor: from n/a through 2.0.0.
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.1
- Disclosed:
- Dec 19, 2023
CVE-2023-37390 on NVD →
Themesflat Addons For Elementor <= 2.0.0 - Unauthenticated PHP Object Injection
critical
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.0 via deserialization of untrusted input through the 'settings' parameter retrieved from the tf_product_filter nopriv AJAX action. This allows unauthenticated attackers to inject a PHP Ob...
- CVSS:
- 9.8
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.1
- Disclosed:
- Aug 7, 2023
CVE-2023-37390 on NVD →
Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.6
unknown
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.6
CVE-2025-3275 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database