Input validation vulnerability in Themesflat Addons For Elementor 2.2.1

A plugin called Themesflat Addons For Elementor on WordPress is at risk of a type of hacking called Stored Cross-Site Scripting. This can happen through various widgets like ‘TF E Slider Widget’, ‘TF Video Widget’, and ‘TF Team Widget’ in versions 2.2.1 and below. The plugin does not properly protect against harmful code being added to web addresses, which means that attackers who have Contributor-level access or higher can insert their own code into pages. This code will run whenever someone visits the affected page.

Detected in:

Themesflat Addons For Elementor open vulnerable versions: >= * <= 2.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.