Input validation vulnerability in All-in-One Addons for Elementor – WidgetKit 2.4.8

A plugin called All-in-One Addons for Elementor – WidgetKit for WordPress has a security issue where hackers can inject harmful code into certain pricing widgets. This can happen in all versions up to 2.4.8 because the code is not properly checked and sanitized. This means that anyone with contributor-level access or higher can potentially add dangerous scripts to pages that will run when someone visits that page.

Detected in:

All-in-One Addons for Elementor – WidgetKit fixed vulnerable versions: >= * <= 2.5.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.