Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-25027 | 1 Ideabox | 1 Powerpack Addons For Elementor | 2022-01-07 | 4.3 MEDIUM | 6.1 MEDIUM |
The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue | |||||
CVE-2021-24263 | 1 Ideabox | 1 Powerpack Addons For Elementor | 2021-05-11 | 3.5 LOW | 5.4 MEDIUM |
The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. |