Vulnerabilities in Jetmonsters
55 resultsVexday analysis
A Jetmonsters apresenta um perfil de risco modesto com 3 CVEs catalogadas, nenhuma sob exploração ativa e sem críticas confirmadas. O inventário recente mostra 2 divulgações nos últimos 90 dias, indicando descobertas contínuas, com a fraqueza dominante concentrada em CWE-266 (problemas de controle de privilégios), sugerindo foco em validação de permissões.
CVE-2024-2138MEDIUMJetWidgets For Elementor <= 1.0.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box WidgetEPSS 0.4%CVE-2020-36840HIGHTimetable and Event Schedule by MotoPress <= 2.3.8 - Missing AuthorizationEPSS 0.4%CVE-2026-90650HIGHMotoPress Hotel Booking <= 6.2.4 - Unauthenticated Stored Cross-Site Scripting via Stripe Webhook Event Object 'id'EPSS 0.4%CVE-2024-1948MEDIUMGetwid – Gutenberg Blocks <= 2.0.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via Block ContentEPSS 0.4%CVE-2024-6491MEDIUMGetwid – Gutenberg Blocks <= 2.0.10 - Missing Authentication to MailChimp API key updateEPSS 0.4%CVE-2026-9228MEDIUMTimetable and Event Schedule by MotoPress <= 2.4.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via action_get_event_data FunctionEPSS 0.4%CVE-2026-57347MEDIUMWordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-31386MEDIUMMultiple WordPress themes affected by Cross-Site Request Forgery vulnerabilityEPSS 0.4%CVE-2025-66078CRITICALWordPress Hotel Booking Lite plugin <= 5.2.3 - Remote Code Execution (RCE) vulnerabilityEPSS 0.4%CVE-2026-57644HIGHWordPress Restaurant Menu by MotoPress plugin <= 2.4.10 - SQL Injection vulnerabilityEPSS 0.4%CVE-2026-28140HIGHWordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-2507MEDIUMJetWidgets For Elementor <= 1.0.16 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Button URLEPSS 0.3%CVE-2025-49914MEDIUMWordPress Restaurant Menu by MotoPress plugin <= 2.4.7 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2023-0086MEDIUMJetWidgets for Elementor <= 1.0.12 - Cross-Site Request Forgery to Settings UpdateEPSS 0.3%CVE-2024-5611MEDIUMStratum – Elementor Widgets <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown WidgetEPSS 0.3%CVE-2024-4626MEDIUMJetWidgets For Elementor <= 1.0.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id ParametersEPSS 0.3%CVE-2024-10872MEDIUMGetwid – Gutenberg Blocks <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2024-10323MEDIUMJetWidgets For Elementor <= 1.0.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File UploadEPSS 0.3%CVE-2024-6489MEDIUMGetwid – Gutenberg Blocks <= 2.0.10 - Missing Authorization to Google API key updateEPSS 0.3%CVE-2026-54196MEDIUMWordPress JetFormBuilder plugin <= 3.6.1 - Privilege Escalation vulnerabilityEPSS 0.3%