POSIMYTH records
42 published records for vendor posimyth.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 23.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')25
- CWE-862 Missing Authorization3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
42 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2021-24175Proof of concept | The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypassposimyth · the plus addons for elementor · CWE-287 | Critical9.8 | — | 14.5% | Apr 5, 2021 |
40Plan | CVE-2021-24949No exploit | The Plus Addons for Elementor Pro < 5.0.7 - Unauthenticated SQL Injectionposimyth · the plus addons for elementor · CWE-89 | Critical9.8 | — | 1.7% | Jan 10, 2022 |
39Monitor | CVE-2023-45657Proof of concept | WordPress Nexter Theme <= 2.0.3 is vulnerable to SQL Injectionposimyth · nexter · CWE-89 | Critical9.8 | — | 1.3% | Nov 6, 2023 |
39Monitor | CVE-2023-47178No exploit | WordPress The Plus Addons for Elementor Pro plugin <= 5.2.8 - Unauthenticated Local File Inclusion vulnerabilityposimyth · the plus addons for elementor · CWE-22 | Critical9.8 | — | 0.6% | May 17, 2024 |
35Monitor | CVE-2021-4331No exploit | The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege Escalationposimyth · the plus addons for elementor · CWE-862 | High8.8 | — | 0.9% | Mar 7, 2023 |
35Monitor | CVE-2024-5455No exploit | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.6 - Authenticated (Contributor+) Local File Inclusionposimyth · the plus addons for elementor · CWE-98 | High8.8 | — | 0.6% | Jun 21, 2024 |
35Monitor | CVE-2024-2203No exploit | The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Clients Widgetposimyth · the plus addons for elementor · CWE-22 | High8.8 | — | 0.6% | Mar 26, 2024 |
35Monitor | CVE-2024-43932No exploit | WordPress The Plus Addons for Elementor plugin <= 5.6.2 - Broken Access Control vulnerabilityposimyth · the plus addons for elementor · CWE-862 | High8.8 | — | 0.6% | Nov 1, 2024 |
35Monitor | CVE-2024-33572No exploit | WordPress Nexter Blocks plugin <= 3.2.5 - Broken Access Control vulnerabilityposimyth · nexter blocks · CWE-862 | High8.8 | — | 0.4% | Jun 9, 2024 |
31Monitor | CVE-2021-24948No exploit | The Plus Addons for Elementor Pro < 5.0.7 - Sensitive Data Disclosureposimyth · the plus addons for elementor · CWE-200 | High7.5 | — | 1.8% | Jan 10, 2022 |
28Monitor | CVE-2023-45751No exploit | WordPress Nexter Extension Plugin <= 2.0.3 is vulnerable to Remote Code Execution (RCE)posimyth · nexter extension · CWE-94 | High7.2 | — | 0.6% | Dec 29, 2023 |
26Monitor | CVE-2021-4332No exploit | The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Readposimyth · the plus addons for elementor · CWE-73 | Medium6.5 | — | 0.8% | Mar 7, 2023 |
25Monitor | CVE-2021-24351Proof of concept | The Plus Addons for Elementor < 4.1.12 - Reflected Cross-Site Scripting (XSS)posimyth · the plus addons for elementor · CWE-79 | Medium6.1 | — | 2.5% | Jun 14, 2021 |
25Monitor | CVE-2021-24358Proof of concept | The Plus Addons for Elementor Page Builder < 4.1.10 - Open Redirectposimyth · the plus addons for elementor · CWE-601 | Medium6.1 | — | 2.3% | Jun 14, 2021 |
25Monitor | CVE-2024-2210No exploit | The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Team Member Listingposimyth · the plus addons for elementor · CWE-22 | Medium6.4 | — | 0.5% | Mar 26, 2024 |
24Monitor | CVE-2023-45750No exploit | WordPress Nexter Extension Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)posimyth · nexter extension · CWE-79 | Medium6.1 | — | 0.4% | Oct 25, 2023 |
24Monitor | CVE-2024-5344No exploit | The Plus Addons for Elementor Page Builder <= 5.5.6 - Reflected Cross-Site Scripting via WP Login and Register Widgetposimyth · the plus addons for elementor · CWE-79 | Medium6.1 | — | 0.3% | Jun 20, 2024 |
21Monitor | CVE-2021-24359No exploit | The Plus Addons for Elementor Page Builder < 4.1.11 - Arbitrary Reset Pwd Email Sendingposimyth · the plus addons for elementor · CWE-284 | Medium5.3 | — | 1.1% | Jun 14, 2021 |
21Monitor | CVE-2024-4484No exploit | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scriposimyth · the plus addons for elementor · CWE-79 | Medium5.4 | — | 0.7% | May 24, 2024 |
21Monitor | CVE-2021-24266No exploit | The Plus Addons for Elementor Page Builder Lite < 2.0.6 - Contributor+ Stored XSSposimyth · the plus addons for elementor page builder lite · CWE-79 | Medium5.4 | — | 0.6% | May 5, 2021 |
21Monitor | CVE-2024-0445No exploit | The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scriptingposimyth · the plus addons for elementor · CWE-79 | Medium5.4 | — | 0.5% | May 14, 2024 |
21Monitor | CVE-2024-3199No exploit | The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widgetposimyth · the plus addons for elementor · CWE-79 | Medium5.4 | — | 0.5% | May 2, 2024 |
21Monitor | CVE-2024-3197No exploit | The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributesposimyth · the plus addons for elementor · CWE-79 | Medium5.4 | — | 0.4% | May 2, 2024 |
21Monitor | CVE-2024-11829No exploit | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scriposimyth · the plus addons for elementor · CWE-79 | Medium5.4 | — | 0.4% | Feb 1, 2025 |
21Monitor | CVE-2024-3718No exploit | The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pricposimyth · the plus addons for elementor · CWE-79 | Medium5.4 | — | 0.4% | May 24, 2024 |
- CVE-2021-2417543Plan
The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
CriticalCVSS 9.8Proof of conceptEPSS 14%posimyth · the plus addons for elementorApr 5, 2021
- CVE-2021-2494940Plan
The Plus Addons for Elementor Pro < 5.0.7 - Unauthenticated SQL Injection
CriticalCVSS 9.8No exploitEPSS 2%posimyth · the plus addons for elementorJan 10, 2022
- CVE-2023-4565739Monitor
WordPress Nexter Theme <= 2.0.3 is vulnerable to SQL Injection
CriticalCVSS 9.8Proof of conceptEPSS 1%posimyth · nexterNov 6, 2023
- CVE-2023-4717839Monitor
WordPress The Plus Addons for Elementor Pro plugin <= 5.2.8 - Unauthenticated Local File Inclusion vulnerability
CriticalCVSS 9.8No exploitEPSS 1%posimyth · the plus addons for elementorMay 17, 2024
- CVE-2021-433135Monitor
The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege Escalation
HighCVSS 8.8No exploitEPSS 1%posimyth · the plus addons for elementorMar 7, 2023
- CVE-2024-545535Monitor
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.6 - Authenticated (Contributor+) Local File Inclusion
HighCVSS 8.8No exploitEPSS 1%posimyth · the plus addons for elementorJun 21, 2024
- CVE-2024-220335Monitor
The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Clients Widget
HighCVSS 8.8No exploitEPSS 1%posimyth · the plus addons for elementorMar 26, 2024
- CVE-2024-4393235Monitor
WordPress The Plus Addons for Elementor plugin <= 5.6.2 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 1%posimyth · the plus addons for elementorNov 1, 2024
- CVE-2024-3357235Monitor
WordPress Nexter Blocks plugin <= 3.2.5 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%posimyth · nexter blocksJun 9, 2024
- CVE-2021-2494831Monitor
The Plus Addons for Elementor Pro < 5.0.7 - Sensitive Data Disclosure
HighCVSS 7.5No exploitEPSS 2%posimyth · the plus addons for elementorJan 10, 2022
- CVE-2023-4575128Monitor
WordPress Nexter Extension Plugin <= 2.0.3 is vulnerable to Remote Code Execution (RCE)
HighCVSS 7.2No exploitEPSS 1%posimyth · nexter extensionDec 29, 2023
- CVE-2021-433226Monitor
The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read
MediumCVSS 6.5No exploitEPSS 1%posimyth · the plus addons for elementorMar 7, 2023
- CVE-2021-2435125Monitor
The Plus Addons for Elementor < 4.1.12 - Reflected Cross-Site Scripting (XSS)
MediumCVSS 6.1Proof of conceptEPSS 2%posimyth · the plus addons for elementorJun 14, 2021
- CVE-2021-2435825Monitor
The Plus Addons for Elementor Page Builder < 4.1.10 - Open Redirect
MediumCVSS 6.1Proof of conceptEPSS 2%posimyth · the plus addons for elementorJun 14, 2021
- CVE-2024-221025Monitor
The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Team Member Listing
MediumCVSS 6.4No exploitEPSS 0%posimyth · the plus addons for elementorMar 26, 2024
- CVE-2023-4575024Monitor
WordPress Nexter Extension Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%posimyth · nexter extensionOct 25, 2023
- CVE-2024-534424Monitor
The Plus Addons for Elementor Page Builder <= 5.5.6 - Reflected Cross-Site Scripting via WP Login and Register Widget
MediumCVSS 6.1No exploitEPSS 0%posimyth · the plus addons for elementorJun 20, 2024
- CVE-2021-2435921Monitor
The Plus Addons for Elementor Page Builder < 4.1.11 - Arbitrary Reset Pwd Email Sending
MediumCVSS 5.3No exploitEPSS 1%posimyth · the plus addons for elementorJun 14, 2021
- CVE-2024-448421Monitor
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scri
MediumCVSS 5.4No exploitEPSS 1%posimyth · the plus addons for elementorMay 24, 2024
- CVE-2021-2426621Monitor
The Plus Addons for Elementor Page Builder Lite < 2.0.6 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%posimyth · the plus addons for elementor page builder liteMay 5, 2021
- CVE-2024-044521Monitor
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%posimyth · the plus addons for elementorMay 14, 2024
- CVE-2024-319921Monitor
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
MediumCVSS 5.4No exploitEPSS 1%posimyth · the plus addons for elementorMay 2, 2024
- CVE-2024-319721Monitor
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes
MediumCVSS 5.4No exploitEPSS 0%posimyth · the plus addons for elementorMay 2, 2024
- CVE-2024-1182921Monitor
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scri
MediumCVSS 5.4No exploitEPSS 0%posimyth · the plus addons for elementorFeb 1, 2025
- CVE-2024-371821Monitor
The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pric
MediumCVSS 5.4No exploitEPSS 0%posimyth · the plus addons for elementorMay 24, 2024