plugin

Void Elementor Post Grid Addon For Elementor Page Builder Vulnerabilities

5 known security issues reported for the Void Elementor Post Grid Addon For Elementor Page Builder WordPress plugin. Most recent disclosed Dec 9, 2024.

1 high 1 medium

Running Void Elementor Post Grid Addon For Elementor Page Builder on your site? Check whether your installed version is affected.

Scan your site free

Void Elementor Post Grid Addon for Elementor Page builder [void-elementor-post-grid-addon-for-elementor-page-builder] < 2.2

unknown

[en] Missing Authorization vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elementor Page builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Void Elementor Post Grid Addon for Elementor Page builder: from n/a through 2.1.10.

Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
Dec 9, 2024

CVE-2023-48750 on NVD →

Void Elementor Post Grid Addon for Elementor Page builder [void-elementor-post-grid-addon-for-elementor-page-builder] < 2.4

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elementor Page builder allows PHP Local File Inclusion.This issue affects Void Elementor Post Grid Addon for Elementor Page builder: from n/a through 2.3.

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Aug 19, 2024

CVE-2024-43281 on NVD →

Void Elementor Post Grid Addon for Elementor Page builder <= 2.3 - Authenticated (Contributor+) Local File Inclusion

high

The Void Elementor Post Grid Addon for Elementor Page builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.3 via the 'display_type' attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitra...

CVSS:
8.8
Affected:
up to 2.3
Fixed in:
2.4
Disclosed:
Aug 16, 2024

CVE-2024-43281 on NVD →

Void Elementor Post Grid Addon for Elementor Page builder <= 2.1.10 - Missing Authorization to Review Notice Dismissal

medium

The Void Elementor Post Grid Addon for Elementor Page builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the void_grid_spare_me() function hooked via admin_init in versions up to, and including, 2.1.10. This makes it possible for unauthenticated attacker...

CVSS:
5.3
Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
Aug 21, 2023

CVE-2023-48750 on NVD →

Void Elementor Post Grid Addon for Elementor Page builder [void-elementor-post-grid-addon-for-elementor-page-builder] < 2.2

unknown

The Void Elementor Post Grid Addon for Elementor Page builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the void_grid_spare_me() function hooked via admin_init in versions up to, and including, 2.1.10. This makes it possible for unauthenticated attacker...

Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
Aug 21, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database