Home/Product/posimyth the plus addons for elementor
Product

posimyth the plus addons for elementor

37 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-1287
< 6.2.3
The Plus Addons for Elementor - Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vuln
6.4MEDIUM
CVE-2024-11829
< 6.2.0
The Plus Addons for Elementor - Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vuln
6.4MEDIUM
CVE-2024-53823
<= 5.6.14
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for
6.5MEDIUM
CVE-2024-10365
< 6.0.4
The Plus Addons for Elementor - Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vuln
4.3MEDIUM
CVE-2024-43932
< 5.6.3
Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page
6.5MEDIUM
CVE-2024-8913
< 5.6.12
The Plus Addons for Elementor - Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vuln
4.3MEDIUM
CVE-2024-43977
< 5.6.3
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for
5.9MEDIUM
CVE-2024-5583
< 5.6.3
The Plus Addons for Elementor - Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vuln
6.4MEDIUM
CVE-2024-6575
< 5.6.3
The Plus Addons for Elementor - Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vuln
6.4MEDIUM
CVE-2024-5763
< 5.6.3
The Plus Addons for Elementor - Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vuln
6.4MEDIUM
CVE-2024-4482
< 5.6.2
The Plus Addons for Elementor - Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vuln
6.4MEDIUM
CVE-2024-4983
< 5.6.1
The Plus Addons for Elementor - Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vuln
6.4MEDIUM
CVE-2024-5455
< 5.6.0
The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i
8.8HIGH
CVE-2024-5344
< 5.6.0
The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘for
6.1MEDIUM
CVE-2024-35709
< 5.5.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for
6.5MEDIUM
CVE-2024-5341
< 5.5.0
The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' at
6.4MEDIUM
CVE-2024-4485
< 5.5.3
The Plus Addons for Elementor - Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vuln
6.4MEDIUM
CVE-2024-4484
< 5.5.3
The Plus Addons for Elementor - Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vuln
6.4MEDIUM
CVE-2024-3718
< 5.5.5
The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's wi
6.4MEDIUM
CVE-2024-2784
< 5.5.5
The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Hover Card widget in a
6.4MEDIUM
CVE-2023-47178
< 5.2.9
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in POSIMYTH Innovation The Plus Addon
8.6HIGH
CVE-2024-2785
< 5.5.0
The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate widget in all
6.4MEDIUM
CVE-2024-0445
< 5.5.0
The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attri
6.4MEDIUM
CVE-2024-34373
< 5.5.0
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for
6.5MEDIUM
CVE-2024-3199
< 5.5.0
The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in al
6.4MEDIUM
CVE-2024-3197
< 5.5.0
The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in the p
6.4MEDIUM
CVE-2024-2210
< 5.4.2
The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,
6.4MEDIUM
CVE-2024-2203
< 5.4.2
The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,
6.4MEDIUM
CVE-2024-1419
< 5.4.1
The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ attribute of
6.4MEDIUM
CVE-2021-4332
<= 2.0.6
The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (p
6.5MEDIUM
CVE-2021-4331
<= 2.0.6
The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (p
8.8HIGH
CVE-2021-24949
< 5.0.7
The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise and escape t
9.8CRITICAL
CVE-2021-24948
< 5.0.7
The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_in
7.5HIGH
CVE-2021-24359
< 4.1.11
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password
5.3MEDIUM
CVE-2021-24358
< 4.1.10
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically
6.1MEDIUM
CVE-2021-24351
< 4.1.12
The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sa
6.1MEDIUM
CVE-2021-24175
< 4.1.7
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to by
9.8CRITICAL
threatengine.sh