Input validation vulnerability in Premium Addons for Elementor 4.10.35

The Premium Addons plugin for Elementor on WordPress has a security issue that allows attackers to inject malicious code through the Countdown widget. This can happen in any version up to and including 4.10.35 because the plugin does not properly clean and protect user input. This means that users with contributor-level or higher access can add harmful scripts to pages, which will run whenever someone views the page.

Detected in:

Premium Addons for Elementor fixed vulnerable versions: >= * <= 4.10.36

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.