Vulnerabilities > Wpdeveloper > Low

DATE CVE VULNERABILITY TITLE RISK
2021-11-23 CVE-2021-24812 Cross-site Scripting vulnerability in Wpdeveloper Betterlinks
The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.
3.5
2021-05-05 CVE-2021-24255 Cross-site Scripting vulnerability in Wpdeveloper Essential Addons for Elementor
The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, both via a similar method.
3.5