Vulnerabilities > Wpkoi

DATE CVE VULNERABILITY TITLE RISK
2024-10-29 CVE-2024-49679 Cross-site Scripting vulnerability in Wpkoi Templates for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPKoi WPKoi Templates for Elementor allows Stored XSS.This issue affects WPKoi Templates for Elementor: from n/a through 3.1.0.
network
low complexity
wpkoi CWE-79
5.4
2024-03-07 CVE-2024-2136 Cross-site Scripting vulnerability in Wpkoi Templates for Elementor
The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget in all versions up to, and including, 2.5.6 due to insufficient input sanitization and output escaping.
network
low complexity
wpkoi CWE-79
5.4