Vulnerabilities (CVE)

Filtered by vendor Posimyth Subscribe
Filtered by product The Plus Addons For Elementor
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24351 1 Posimyth 1 The Plus Addons For Elementor 2021-06-21 4.3 MEDIUM 6.1 MEDIUM
The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scripting (exploitable on both unauthenticated and authenticated users)
CVE-2021-24359 1 Posimyth 1 The Plus Addons For Elementor 2021-06-18 5.0 MEDIUM 5.3 MEDIUM
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legitimate user, allowing an attacker to send an arbitrary reset password email to a registered user on behalf of the WordPress site. Such issue could be chained with an open redirect (CVE-2021-24358) in version below 4.1.10, to include a crafted password reset link in the email, which would lead to an account takeover.
CVE-2021-24358 1 Posimyth 1 The Plus Addons For Elementor 2021-06-18 5.8 MEDIUM 6.1 MEDIUM
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue.