ESSENTIAL ADDONS v5.0.6 for Elementor

thePLUS

Well-known member
Master
Diamond
Elite
Joined
Apr 27, 2021
Messages
257
Reaction score
1,507
Points
93
NullCash
11,476
Essential-Addons-pro.png

ESSENTIAL ADDONS v5.0.6 for Elementor | +INFO

Essential Addons for Elementor
- increases the functionality of Elementor PRO page builder by adding many different elements to it:
Post Block (Flex),
Post Grid (Masonry),
Post Timeline,
Fancy Text,
Creative Buttons,
Countdown,
Team Members,
Testimonials,
WooCommerce Product Grid,
Contact Form 7,
weForms,
Info Box,
Flip Box,
Twocolor Title,
Call to Action,
Lightbox & Modal,
Testimonials Slider,
Image Compare,
Interactive Promo,
Interactive Promo,
Static Product,
Table Prizes,
Flip Carousel,
Interactive Mapas,
Ninja Shapes.
 

Attachments

  • essential-addons-elementor+v5.0.6.zip
    1.9 MB · Views: 6

hexer

Member
XNullUser
Joined
Jul 25, 2021
Messages
65
Reaction score
0
Points
6
NullCash
5
Thank you!

Please notice:

Essential Addons for Elementor, a popular plugin with more than a million active installs, has patched a critical vulnerability that would allow for a local file inclusion attack.

The vulnerability was discovered by security researcher Wai Yan Myo Thet and reported to Patchstack on January 25, 2022. Patchstack customers received a virtual patch the same day. The issue was already known to the plugin’s developers, WPDeveloper, who issued two insufficient patches before it was ultimately fixed in version 5.0.5.

Patchstack published a summary of the vulnerability and explained how WordPress sites using the plugin could be compromised:

This vulnerability allows any user, regardless of their authentication or authorization status, to perform a local file inclusion attack. This attack can be used to include local files on the filesystem of the website, such as /etc/passwd. This can also be used to perform RCE by including a file with malicious PHP code that normally cannot be executed.
It’s important to note that the vulnerability primarily impacts users who have the dynamic gallery and product gallery widgets in use.
The plugin’s changelog makes the update seem more like an enhancement than a serious security concern, so users may not be fully aware that they need to update:
5.0.5 – 28/01/2022
Improved: Enhanced Security to prevent inclusion of unwanted file form remote server through ajax request
5.0.4 – 27/01/2022
Improved: Sanitized template file paths for Security Enhancement
Added: Support for new Capability Queries for WordPress 5.9
Fixed: Elementor Popups not being triggered
Few minor bug fixes & improvements

All versions earlier than 5.0.5 are considered vulnerable. WordPress.org stats don’t break down active installs according to minor versions, but approximately 54% of the plugin’s users are running versions older than 5.0.
 

uko

Member
XNullUser
Joined
Apr 14, 2021
Messages
635
Reaction score
11
Points
18
NullCash
39
thaks for sharing this addonI try it
 

orstem

Member
XNullUser
Joined
Sep 28, 2021
Messages
80
Reaction score
85
Points
18
NullCash
19
Many thanks for it, even if its a bit old
 
Top