浏览 21+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-2600 | ElementsKit Elementor Addons and Templates <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Simple Tab Widget | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 6.4 | 2026-04-04 07:41:58 | Deep Dive |
| CVE-2026-23693 | ElementsKit Elementor Addons < 3.7.9 Unauthenticated Mailchimp REST Endpoint | Roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Critical | 10.0 | 2026-02-23 20:33:55 | Deep Dive |
| CVE-2025-3614 | ElementsKit Elementor Addons and Templates <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 6.4 | 2025-07-24 22:23:37 | Deep Dive |
| CVE-2025-4479 | ElementsKit Lite <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 6.4 | 2025-06-19 03:40:14 | Deep Dive |
| CVE-2024-11180 | ElementsKit Elementor addons <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 6.4 | 2025-03-29 07:23:45 | Deep Dive |
| CVE-2025-0968 | ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 5.3 | 2025-02-19 11:10:39 | Deep Dive |
| CVE-2025-1005 | ElementsKit Elementor addons <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 6.4 | 2025-02-15 09:24:22 | Deep Dive |
| CVE-2024-37255 | WordPress ElementsKit Lite plugin <= 3.1.4 - Unauthenticated Broken Access Control vulnerability | Roxnor | ElementsKit Elementor addons Lite | Medium | 5.3 | 2024-11-01 14:18:29 | Deep Dive |
| CVE-2024-10091 | ElementsKit Elementor addons <= 3.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 6.4 | 2024-10-26 02:31:31 | Deep Dive |
| CVE-2024-8546 | ElementsKit Elementor addons <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 6.4 | 2024-09-25 12:44:13 | Deep Dive |
| CVE-2024-6455 | ElementsKit Elementor addons <= 3.2.0 - Unauthenticated Information Exposure via ekit_widgetarea_content Function | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 5.3 | 2024-07-18 20:32:38 | Deep Dive |
| CVE-2024-3650 | WordPress plugin ElementsKit Elementor addons 安全漏洞 | xpeedstudio | ElementsKit Elementor addons and Templates Library | Medium | 6.4 | 2024-05-02 16:52:26 | Deep Dive |
| CVE-2024-3499 | ElementsKit Elementor addons <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Module | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | High | 8.8 | 2024-05-02 16:52:10 | Deep Dive |
| CVE-2024-32505 | WordPress ElementsKit Elementor addons plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability | Roxnor | ElementsKit Elementor addons Lite | Medium | 6.5 | 2024-04-17 09:54:18 | Deep Dive |
| CVE-2024-2803 | ElementsKit Elementor addons <= 3.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 6.4 | 2024-04-04 01:56:58 | Deep Dive |
| CVE-2024-1238 | ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 6.4 | 2024-03-30 04:31:10 | Deep Dive |
| CVE-2024-2047 | ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Local File Inclusion in render_raw | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | High | 8.8 | 2024-03-30 04:31:08 | Deep Dive |
| CVE-2023-6525 | ElementsKit Elementor addons <= 3.0.3 - Authenticated(Editor+) Stored Cross-Site Scripting | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 5.5 | 2024-03-16 02:34:28 | Deep Dive |
| CVE-2024-2042 | ElementsKit Elementor addons <= 3.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 6.4 | 2024-03-16 02:34:28 | Deep Dive |
| CVE-2024-1239 | ElementsKit Elementor addons <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 6.4 | 2024-03-16 02:34:27 | Deep Dive |