Ideabox develops a modest line of WordPress plugin extensions for popular page builders such as Elementor and Beaver Builder, which expand template and design functionality for site builders. The vulnerability profile centers on web-layer input handling and access-control issues, including cross-site scripting, cross-site request forgery, PHP remote file inclusion, and permission assignment flaws that are characteristic of WordPress plugin ecosystems where plugins often operate with broad administrative scope. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ideabox over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3668HIGH The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting | Jun 8, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-39633HIGH Improper Privilege Management vulnerability in IdeaBox PowerPack for Beaver Builder allows Privilege Escalation.This issue affects PowerPack for Beaver Builder: from n/a through 2. | Aug 1, 2024 | 8.8 | 22 | NO | NO |
CVE-2022-0176MEDIUM The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflec | Feb 14, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-25027MEDIUM The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Re | Jan 3, 2022 | 6.1 | 22 | NO | NO |
CVE-2024-37410HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in IdeaBox Creations PowerPack Lite for Beaver Builder powerpa | Jul 9, 2024 | 7.2 | 20 | NO | NO |
CVE-2024-43330MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack for Beaver Builder allows Reflected XSS.Thi | Aug 18, 2024 | 6.1 | 19 | NO | NO |
CVE-2021-24263MEDIUM The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by | May 5, 2021 | 5.4 | 19 | NO | NO |
CVE-2024-12239MEDIUM The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navigate parameter in all versions up to, and including, 1.3.0.5 | Dec 17, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-1411MEDIUM The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the settings of the Twitter Buttons Widget in all versions up to, and inclu | Feb 29, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-37409MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack Lite for Beaver Builder powerpack-addon-for-beaver | Jul 22, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ideabox.
Media articles that mention a CVE ID that affects a product developed by Ideabox — matched by CVE ID, not by vendor name.