Vulnerabilities > Exclusiveaddons

DATE CVE VULNERABILITY TITLE RISK
2025-02-28 CVE-2025-1571 Cross-site Scripting vulnerability in Exclusiveaddons Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Image Comparison Widgets in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
exclusiveaddons CWE-79
5.4
2024-10-29 CVE-2024-10312 Unspecified vulnerability in Exclusiveaddons Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.4 via the render function in elements/tabs/tabs.php.
network
low complexity
exclusiveaddons
4.3
2024-10-17 CVE-2024-49292 Cross-site Scripting vulnerability in Exclusiveaddons Exclusive Addons for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.7.1.
network
low complexity
exclusiveaddons CWE-79
5.4
2024-06-26 CVE-2024-5332 Cross-site Scripting vulnerability in Exclusiveaddons Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Card widget in all versions up to, and including, 2.6.9.8 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
exclusiveaddons CWE-79
5.4
2024-05-15 CVE-2024-4618 Cross-site Scripting vulnerability in Exclusiveaddons Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member widget in all versions up to, and including, 2.6.9.6 due to insufficient input sanitization and output escaping on user supplied 'url' attribute.
network
low complexity
exclusiveaddons CWE-79
5.4
2024-05-02 CVE-2024-2503 Cross-site Scripting vulnerability in Exclusiveaddons Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid Widget in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping on user supplied tags.
network
low complexity
exclusiveaddons CWE-79
5.4
2024-05-02 CVE-2024-2750 Cross-site Scripting vulnerability in Exclusiveaddons Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of the Button widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping.
network
low complexity
exclusiveaddons CWE-79
5.4
2024-05-02 CVE-2024-2751 Cross-site Scripting vulnerability in Exclusiveaddons Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exad_infobox_animating_mask_style’ parameter in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping.
network
low complexity
exclusiveaddons CWE-79
5.4
2024-05-02 CVE-2024-3489 Cross-site Scripting vulnerability in Exclusiveaddons Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Countdown Expired Title in all versions up to, and including, 2.6.9.4 due to insufficient input sanitization and output escaping.
network
low complexity
exclusiveaddons CWE-79
5.4
2024-05-02 CVE-2024-3985 Cross-site Scripting vulnerability in Exclusiveaddons Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Call to Action widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
exclusiveaddons CWE-79
5.4