PowerPack Pro for Elementor
by WordPress
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-42629 | Hig | 0.57 | 8.8 | 0.00 | Jun 17, 2026 | Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions. | ||
| CVE-2024-39634 | Hig | 0.57 | 8.8 | 0.00 | Aug 1, 2024 | Improper Privilege Management vulnerability in IdeaBox PowerPack Pro for Elementor allows Privilege Escalation.This issue affects PowerPack Pro for Elementor: from n/a through 2.10.14. | ||
| CVE-2024-3668 | Hig | 0.57 | 8.8 | 0.00 | Jun 8, 2024 | The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible… | ||
| CVE-2024-24844 | Hig | 0.49 | 7.5 | 0.00 | Dec 23, 2025 | Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PowerPack Pro for Elementor: from n/a through 2.10.6. | ||
| CVE-2024-24843 | Hig | 0.46 | 7.1 | 0.00 | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Addons for Elementor PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a before 2.10.8. | ||
| CVE-2023-49739 | Hig | 0.46 | 7.1 | 0.00 | Dec 14, 2023 | Vulnerability in IdeaBox Creations PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a through 2.9.23. |
- risk 0.57cvss 8.8epss 0.00
Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.
- risk 0.57cvss 8.8epss 0.00
Improper Privilege Management vulnerability in IdeaBox PowerPack Pro for Elementor allows Privilege Escalation.This issue affects PowerPack Pro for Elementor: from n/a through 2.10.14.
- risk 0.57cvss 8.8epss 0.00
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible…
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PowerPack Pro for Elementor: from n/a through 2.10.6.
- risk 0.46cvss 7.1epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Addons for Elementor PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a before 2.10.8.
- risk 0.46cvss 7.1epss 0.00
Vulnerability in IdeaBox Creations PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a through 2.9.23.