Medium 6.4
2025-09-10< 2.9.5
PowerPack Lite for Elementor <= 2.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting Via 'cursor_url'
Minimum safe version
2.9.10
Update to 2.9.10 or later to address 14 fixable vulnerabilities
PowerPack Lite for Elementor <= 2.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting Via 'cursor_url'
CVE-2026-32430
PowerPack Elementor Addons (Free Widgets, Extensions and Templates) <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2024-10692
CVE-2024-5787
CVE-2024-5327
CVE-2024-2492
CVE-2024-2491
CVE-2024-1411
CVE-2024-1055
CVE-2023-6984
WordPress PowerPack Addons for Elementor plugin <= 2.3.1 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
CVE-2021-24263
CVE-2021-25027