Vulnerabilities > Brainstormforce > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-05-05 CVE-2021-24271 Unspecified vulnerability in Brainstormforce Ultimate Addons for Elementor
The “Ultimate Addons for Elementor” WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
network
low complexity
brainstormforce
5.4
2021-05-05 CVE-2021-24256 Unspecified vulnerability in Brainstormforce Elementor - Header, Footer & Blocks Template
The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
network
low complexity
brainstormforce
5.4
2020-05-17 CVE-2020-13125 Unspecified vulnerability in Brainstormforce Ultimate Addons for Elementor
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126.
network
low complexity
brainstormforce
6.5
2019-08-21 CVE-2018-20977 Cross-site Scripting vulnerability in Brainstormforce Schema
The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page.
network
low complexity
brainstormforce CWE-79
6.1