CVE-2024-13362
Events Addon for Elementor
Minimum safe version
2.3.0
Update to 2.3.0 or later to address 15 fixable vulnerabilities
Events Addon for Elementor <= 2.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typewriter and Countdown Widgets
CVE-2024-12061
CVE-2024-54315
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-49264
CVE-2024-4669
Events Addon for Elementor < 2.1.3 - Cross-Site Request Forgery
CVE-2023-47827
Events Addon for Elementor <= 2.1.2 - Cross-Site Request Forgery
Events Addon for Elementor <= 2.1.2 - Missing Authorization
WordPress Events Addon for Elementor Plugin < 2.0.3 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Events Addon for Elementor plugin < 1.9.8 - Sensitive Information Disclosure vulnerability
WordPress Events Addon for Elementor plugin < 1.9.8 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability