Vulnerabilities > Wpmet > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-04-22 CVE-2025-46253 Cross-site Scripting vulnerability in Wpmet Gutenkit
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit allows Stored XSS.
network
low complexity
wpmet CWE-79
5.4
2025-02-28 CVE-2025-1506 Cross-Site Request Forgery (CSRF) vulnerability in Wpmet WP Social Login and Register Social Counter
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.0.
network
low complexity
wpmet CWE-352
4.3
2025-02-19 CVE-2025-0968 Missing Authorization vulnerability in Wpmet Elementskit Elementor Addons
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function.
network
low complexity
wpmet CWE-862
5.3
2025-02-15 CVE-2025-1005 Cross-site Scripting vulnerability in Wpmet Elementskit Elementor Addons
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpmet CWE-79
5.4
2025-01-28 CVE-2025-0321 Cross-site Scripting vulnerability in Wpmet Elementskit
The ElementsKit Pro plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping.
network
low complexity
wpmet CWE-79
5.4
2024-11-01 CVE-2024-37255 Unspecified vulnerability in Wpmet Elements KIT Elementor Addons
Missing Authorization vulnerability in Wpmet Elements kit Elementor addons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elements kit Elementor addons: from n/a through 3.1.4.
network
low complexity
wpmet
5.3
2024-10-26 CVE-2024-10091 Cross-site Scripting vulnerability in Wpmet Elements KIT Elementor Addons
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpmet CWE-79
5.4
2024-09-25 CVE-2024-8546 Cross-site Scripting vulnerability in Wpmet Elementskit Elementor Addons
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpmet CWE-79
5.4
2024-09-23 CVE-2024-43996 Path Traversal vulnerability in Wpmet Elementskit
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit Pro allows PHP Local File Inclusion.This issue affects ElementsKit Pro: from n/a through 3.6.0.
network
low complexity
wpmet CWE-22
6.5
2024-08-15 CVE-2024-7063 Unspecified vulnerability in Wpmet Elementskit
The ElementsKit Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.6 via the 'render_raw' function.
network
low complexity
wpmet
4.3