Vulnerabilities > Sktthemes

DATE CVE VULNERABILITY TITLE RISK
2025-02-12 CVE-2024-13665 Cross-site Scripting vulnerability in Sktthemes Admire Extra
The Admire Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'space' shortcode in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
sktthemes CWE-79
5.4
2024-11-09 CVE-2024-10693 Authorization Bypass Through User-Controlled Key vulnerability in Sktthemes SKT Addons for Elementor
The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.3 via the Unfold widget due to insufficient restrictions on which posts can be included.
network
low complexity
sktthemes CWE-639
4.3
2024-09-18 CVE-2024-43995 Cross-site Scripting vulnerability in Sktthemes Posterity
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sonalsinha21 Posterity allows Stored XSS.This issue affects Posterity: from n/a through 3.6.
network
low complexity
sktthemes CWE-79
5.4
2024-09-17 CVE-2024-44007 Cross-site Scripting vulnerability in Sktthemes SKT Templates
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Templates – Elementor & Gutenberg templates allows Reflected XSS.This issue affects SKT Templates – Elementor & Gutenberg templates: from n/a through 6.14.
network
low complexity
sktthemes CWE-79
6.1
2024-08-29 CVE-2024-43946 Cross-site Scripting vulnerability in Sktthemes SKT Blocks
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Blocks – Gutenberg based Page Builder allows Stored XSS.This issue affects SKT Blocks – Gutenberg based Page Builder: from n/a through 1.5.
network
low complexity
sktthemes CWE-79
5.4
2024-07-20 CVE-2024-38674 Unspecified vulnerability in Sktthemes SKT Addons for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Addons for Elementor allows Stored XSS.This issue affects SKT Addons for Elementor: from n/a through 3.0.
network
low complexity
sktthemes
5.4
2024-06-08 CVE-2024-5091 Cross-site Scripting vulnerability in Sktthemes SKT Addons for Elementor
The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Age Gate and Creative Slider widgets in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
sktthemes CWE-79
5.4
2024-05-14 CVE-2024-34436 Unspecified vulnerability in Sktthemes SKT Addons for Elementor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Addons for Elementor allows Stored XSS.This issue affects SKT Addons for Elementor: from n/a through 1.8.
network
low complexity
sktthemes
5.4
2024-05-14 CVE-2024-34445 Unspecified vulnerability in Sktthemes SKT Addons for Elementor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Addons for Elementor allows Stored XSS.This issue affects SKT Addons for Elementor: from n/a through 1.8.
network
low complexity
sktthemes
5.4