Vulnerabilities > Wpmet > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-25 CVE-2024-8546 Cross-site Scripting vulnerability in Wpmet Elementskit Elementor Addons
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpmet CWE-79
5.4
2024-06-15 CVE-2024-5263 Cross-site Scripting vulnerability in Wpmet Elementskit
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and Table widgets in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpmet CWE-79
5.4
2024-01-19 CVE-2022-47160 Unspecified vulnerability in Wpmet WP Social Login and Register Social Counter
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Counter.This issue affects Wp Social Login and Register Social Counter: from n/a through 1.9.0.
network
low complexity
wpmet
6.5
2024-01-11 CVE-2023-6582 Unspecified vulnerability in Wpmet Elements KIT Elementor Addons
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function.
network
low complexity
wpmet
5.3
2024-01-09 CVE-2023-6788 Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Metform Elementor Contact Form Builder
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.1.
network
low complexity
wpmet CWE-352
5.4
2023-08-31 CVE-2023-0689 Unspecified vulnerability in Wpmet Metform Elementor Contact Form Builder
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name' shortcode in versions up to, and including, 3.3.1.
network
low complexity
wpmet
4.3
2023-07-12 CVE-2023-2517 Unspecified vulnerability in Wpmet Metform Elementor Contact Form Builder
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.2.
network
low complexity
wpmet
4.3
2023-06-23 CVE-2023-28751 Cross-site Scripting vulnerability in Wpmet WP Ultimate Review 2.0.3
Auth.
network
low complexity
wpmet CWE-79
4.8
2023-06-09 CVE-2023-0688 Unspecified vulnerability in Wpmet Metform Elementor Contact Form Builder
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' shortcode in versions up to, and including, 3.3.1.
network
low complexity
wpmet
6.5
2023-06-09 CVE-2023-0691 Unspecified vulnerability in Wpmet Metform Elementor Contact Form Builder
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_last_name' shortcode in versions up to, and including, 3.3.1.
network
low complexity
wpmet
4.3