| CVE-2024-5542 | Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Navigation Menu Widget | litonice13 | Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits | High | 7.2 | 2024-06-07 12:33:43 | Deep Dive |
| CVE-2024-5001 | Image Hover Effects for Elementor with Lightbox and Flipbox <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via _id, oxi_addons_f_title_tag, and content_description_tag Parameters | biplob018 | Image Hover Effects for Elementor with Lightbox and Flipbox | Medium | 6.4 | 2024-06-06 02:02:58 | Deep Dive |
| CVE-2024-3134 | Master Addons for Elementor <= 2.0.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | litonice13 | Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits | Medium | 6.4 | 2024-05-16 21:30:56 | Deep Dive |
| CVE-2024-4580 | Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | litonice13 | Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits | Medium | 6.4 | 2024-05-16 11:33:33 | Deep Dive |
| CVE-2024-1166 | Image Hover Effects - Elementor Addon <= 1.4.1 - Authenticated(Contributor+) DOM-based Stored Cross-Site Scripting via Image Hover Effects Widget | blocksera | Image Hover Effects – Elementor Addon | Medium | 6.4 | 2024-05-09 20:03:25 | Deep Dive |
| CVE-2024-4265 | Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.5.9 - Contributor+ Stored Cross-Site Scripting | litonice13 | Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits | Medium | 6.4 | 2024-05-02 16:52:29 | Deep Dive |
| CVE-2024-29936 | WordPress Image Hover Effects – Elementor Addon plugin <= 1.4 - Cross Site Scripting (XSS) vulnerability | Blocksera | Image Hover Effects – Elementor Addon | Medium | 6.5 | 2024-03-27 10:19:48 | Deep Dive |
| CVE-2024-2139 | Master Addons for Elementor <= 2.0.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget | litonice13 | Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits | Medium | 6.4 | 2024-03-27 01:56:47 | Deep Dive |
| CVE-2023-47552 | WordPress Image Hover Effects Plugin <= 5.5 is vulnerable to Cross Site Request Forgery (CSRF) | Labib Ahmed | Image Hover Effects – WordPress Plugin | Medium | 5.4 | 2023-11-18 21:45:38 | Deep Dive |
| CVE-2023-23681 | WordPress Image Hover Effects For WPBakery Page Builder Plugin <= 4.0 is vulnerable to Cross Site Scripting (XSS) | Labib Ahmed | Image Hover Effects For WPBakery Page Builder | Medium | 6.5 | 2023-03-30 11:06:21 | Deep Dive |
| CVE-2022-45831 | WordPress Image Hover Effects - Caption Hover with Carousel Plugin <= 2.8 is vulnerable to Cross Site Scripting (XSS) | biplob018 | Image Hover Effects for Elementor with Lightbox and Flipbox | High | 7.1 | 2023-03-28 07:15:46 | Deep Dive |
| CVE-2022-4207 | WordPress plugin Image Hover Effects Ultimate 跨站脚本漏洞 | biplob018 | Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) | Medium | 5.5 | 2022-12-13 20:18:37 | Deep Dive |
| CVE-2022-4010 | Image Hover Effects < 5.5 - Admin+ Stored XSS | Unknown | Image Hover Effects | 中危 | - | 2022-12-12 17:54:51 | Deep Dive |
| CVE-2022-3601 | Image Hover Effects Css3 <= 4.5 - Admin+ Stored XSS | Unknown | Image Hover Effects Css3 | 中危 | - | 2022-11-28 13:47:06 | Deep Dive |
| CVE-2022-42459 | WordPress Image Hover Effects Ultimate plugin <= 9.7.1 - Auth. WordPress Options Change vulnerability | Biplob Adhikari | Image Hover Effects Ultimate (WordPress plugin) | High | 7.2 | 2022-11-18 22:17:20 | Deep Dive |
| CVE-2022-2937 | Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Title & Description | biplob018 | Image Hover Effects Ultimate | Medium | 6.4 | 2022-09-23 13:54:15 | Deep Dive |
| CVE-2022-2935 | Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Media URL | biplob018 | Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) | Medium | 6.4 | 2022-09-06 17:19:01 | Deep Dive |
| CVE-2022-2936 | Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Video Link | biplob018 | Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) | Medium | 6.4 | 2022-09-06 17:19:00 | Deep Dive |
| CVE-2022-29447 | WordPress Hover Effects plugin <= 2.1 - Authenticated Local File Inclusion (LFI) vulnerability | Wow-Company | Hover Effects – easily create any hover effect (WordPress plugin) | Medium | 6.8 | 2022-05-20 20:17:03 | Deep Dive |
| CVE-2022-29424 | WordPress Image Hover Effects Ultimate plugin <= 9.7.1 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability | Biplob Adhikari | Image Hover Effects Ultimate (WordPress plugin) | Medium | 4.8 | 2022-05-20 19:57:07 | Deep Dive |