Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

elfsight — Vulnerabilities & Security Advisories 9

Browse all 9 CVE security advisories affecting elfsight. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Elfsight provides website widgets and plugins for businesses to integrate third-party functionality. Historically, vulnerabilities have frequently involved cross-site scripting (XSS) and remote code execution (RCE) due to improper input validation and insecure deserialization. Privilege escalation issues have also been documented in administrative interfaces. The platform's security posture has been impacted by multiple CVEs, with several critical flaws allowing unauthorized access or complete compromise of affected sites. While no major public breaches have been widely reported, the consistent pattern of vulnerabilities suggests potential risks for unpatched implementations, particularly in environments where default credentials remain unchanged or security updates are delayed.

CVE ID Title CVSS Severity Published
CVE-2026-39696 WordPress Elfsight WhatsApp Chat CC plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability — Elfsight WhatsApp Chat CC CWE-79 6.5 Medium 2026-04-08
CVE-2025-31045 WordPress elfsight Contact Form widget plugin <= 2.3.1 - Sensitive Data Exposure Vulnerability — elfsight Contact Form widget CWE-497 7.5 High 2025-06-09
CVE-2025-31588 WordPress Elfsight Testimonials Slider plugin <= 1.0.1 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability — Elfsight Testimonials Slider CWE-352 5.4 Medium 2025-03-31
CVE-2025-31587 WordPress Elfsight Testimonials Slider plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability — Elfsight Testimonials Slider CWE-79 5.9 Medium 2025-03-31
CVE-2025-31584 WordPress Elfsight Testimonials Slider plugin <= 1.0.1 - Broken Access Control vulnerability — Elfsight Testimonials Slider CWE-862 5.4 Medium 2025-03-31
CVE-2025-26561 WordPress Elfsight Yottie Lite Plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerability — Elfsight Yottie Lite CWE-79 5.9 Medium 2025-02-13
CVE-2024-10390 Elfsight Telegram Chat CC <= 1.1.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting — Elfsight Telegram Chat CC CWE-862 6.4 Medium 2024-11-18
CVE-2024-4102 Pricing Table <= 2.0.1 - Missing Authorization — Pricing Table CWE-862 5.4 Medium 2024-07-09
CVE-2024-4100 Pricing Table <= 2.0.1 - Cross-Site Request Forgery via ajax() — Pricing Table CWE-352 5.3 Medium 2024-07-09

This page lists every published CVE security advisory associated with elfsight. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.