Skip to main content

Vendor/product archive

crocoblock / jetwidgets_for_elementor CVEs

Beta · best-effort

7 CVEs tagged to crocoblock / jetwidgets_for_elementor0 Critical, 0 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2024-10323

Published Nov 12, 2024

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.0.18 due to in…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4626

Published Jun 20, 2024

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_type’ and 'id' parameters in all versions up to, and including, 1.0.…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2507

Published Apr 9, 2024

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL in all versions up to, and including, 1.0.16 due to insuff…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2138

Published Apr 9, 2024

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animated Box widget in all versions up to, and including, 1.0.15 due to insu…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0034

Published Feb 13, 2023

The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shor…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0086

Published Jan 5, 2023

The JetWidgets for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.12. This is due to missing nonce validation on…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24268

Published May 5, 2021

The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contrib…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1