Vulnerabilities > Ideabox > Powerpack Addons FOR Elementor > 2.6.17

DATE CVE VULNERABILITY TITLE RISK
2024-02-07 CVE-2024-1055 Cross-site Scripting vulnerability in Ideabox Powerpack Addons for Elementor
The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's buttons in all versions up to, and including, 2.7.14 due to insufficient input sanitization and output escaping on user supplied URL values.
network
low complexity
ideabox CWE-79
5.4
2024-01-03 CVE-2023-6984 Cross-Site Request Forgery (CSRF) vulnerability in Ideabox Powerpack Addons for Elementor
The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.13.
network
low complexity
ideabox CWE-352
4.3