plugin

Wpkoi Templates For Elementor Vulnerabilities

6 known security issues reported for the Wpkoi Templates For Elementor WordPress plugin. Most recent disclosed Dec 6, 2025.

6 medium

Running Wpkoi Templates For Elementor on your site? Check whether your installed version is affected.

Scan your site free

WPKoi Templates for Elementor <= 3.4.4 - Missing Authorization

medium

The WPKoi Templates for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.4.4
Fixed in:
3.4.5
Disclosed:
Dec 6, 2025

CVE-2025-64274 on NVD →

WPKoi Templates for Elementor <= 3.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr...

CVSS:
6.4
Affected:
up to 3.4.3
Fixed in:
3.4.4
Disclosed:
Sep 22, 2025

CVE-2025-57999 on NVD →

WPKoi Templates for Elementor <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr...

CVSS:
6.4
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Dec 30, 2024

CVE-2024-56241 on NVD →

WPKoi Templates for Elementor <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr...

CVSS:
6.4
Affected:
up to 3.1.0
Fixed in:
3.1.1
Disclosed:
Oct 21, 2024

CVE-2024-49679 on NVD →

WPKoi Templates for Elementor <= 2.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Parameters

medium

The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id', 'mixColor', 'backgroundColor', 'saveInCookies', and 'autoMatchOsTheme' parameters in all versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible f...

CVSS:
6.4
Affected:
up to 2.5.9
Fixed in:
2.5.11
Disclosed:
May 21, 2024

CVE-2024-4980 on NVD →

WPKoi Templates for Elementor <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget

medium

The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget in all versions up to, and including, 2.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access an...

CVSS:
6.4
Affected:
up to 2.5.6
Fixed in:
2.5.7
Disclosed:
Mar 6, 2024

CVE-2024-2136 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database