Medium 6.4
2025-12-13< 2.2.8
Enter Addons <= 2.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown and Image Comparison Widgets
Minimum safe version
2.3.3
Update to 2.3.3 or later to address 10 fixable vulnerabilities
Enter Addons <= 2.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown and Image Comparison Widgets
CVE-2026-25014
WordPress Enter Addons Plugin <= 2.1.9 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-10868
CVE-2024-47625
CVE-2024-7611
CVE-2024-43225
CVE-2024-37263
CVE-2024-3680
CVE-2024-3831