Codeless develops WordPress plugin extensions centered on the CoWidgets suite, which integrates with the Elementor page builder to provide design and functionality components. The recurring vulnerability surface reflects the web-facing and user-input handling demands of plugin architecture, with exposure clustering around cross-site scripting, path traversal, and authorization-bypass weaknesses typical of content-management-layer software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codeless over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5179HIGH The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.2 via the 'item_style' and 'style' parameters. | Jun 6, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-37419HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Codeless Cowidgets – Elementor Addons allows Path Traversal.This issue affects Cowid | Jul 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-53786MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons cowidgets-elementor-addons allows Stored | Nov 30, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-8960MEDIUM The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insuffici | Nov 9, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-35782MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons allows Stored XSS.This issue affe | Jun 4, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-4697MEDIUM The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_tag’ parameter in all versions up to, and including, 1.1.2 due t | Jun 4, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-10779MEDIUM The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.0 via the 'ce_template' shortcode due to insuf | Nov 9, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codeless.
Media articles that mention a CVE ID that affects a product developed by Codeless — matched by CVE ID, not by vendor name.