Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Fancy Text Widget` And `Countdown Widget`
Sina Extension for Elementor
Minimum safe version
3.7.1
Update to 3.7.1 or later to address 18 fixable vulnerabilities
Sina Extension for Elementor <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Sina Posts`, `Sina Blog Post` and `Sina Table` Widgets
CVE-2025-49262
Sina Extension for Elementor <= 3.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text, Countdown Widget, and Login Form Shortcodes
CVE-2024-12624
CVE-2024-9540
CVE-2024-5260
CVE-2024-5036
CVE-2024-35703
CVE-2024-4373
CVE-2024-4333
CVE-2024-34384
CVE-2024-3988
CVE-2024-29935
WordPress Sina Extension For Elementor plugin <= 2.2.0 - Local File Inclusion (LFI) vulnerability
WordPress Sina Extension for Elementor plugin <= 3.3.11 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
CVE-2019-15839
CVE-2021-24269