Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Sina Extension For Elementor — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
sina-extension-for-elementor
- 40000+ instalaciones activas
elementor addonelementor addonselementor templateselementor widgetheader footer builder
Estado de mantenimiento
Vulnerabilidades conocidas
16 CVEs conocidos registrados para Sina Extension For Elementor.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2025-49262
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.7.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.7.0
|
3.7.0 |
2025-06-05 |
—
|
|
CVE-2024-12624
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.6.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 3.6.0
|
3.6.0 |
2025-01-06 |
—
|
|
CVE-2024-9540
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.5.8 |
Exposición de información sensible a un actor no autorizado |
Media
4,3
|
< 3.5.8
|
3.5.8 |
2024-10-15 |
—
|
|
CVE-2024-5260
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.5.6 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.5.6
|
3.5.6 |
2024-07-01 |
—
|
|
CVE-2024-5036
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.5.5 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.5.5
|
3.5.5 |
2024-06-19 |
—
|
|
CVE-2024-35703
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.5.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.5.4
|
3.5.4 |
2024-06-06 |
—
|
|
CVE-2024-4373
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.5.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.5.4
|
3.5.4 |
2024-05-14 |
—
|
|
CVE-2024-4333
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.5.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.5.4
|
3.5.4 |
2024-05-13 |
—
|
CVE-2025-49262
The Sina Extension for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-12624
The Sina Extension for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina Image Differ widget in all versions up to, and including, 3.5.91 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-9540
The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.7 via the render function in widgets/advanced/sina-modal-box.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft Elementor template data.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-5260
The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘read_more_text’ parameter in all versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-5036
The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-35703
<p>WordPress Sina Extension for Elementor Plugin <= 3.5.3 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Sina Extension for Elementor</p><p>Link: https://wordpress.org/plugins/sina-extension-for-elementor/#developers</p><p>Affected Version <= 3.5.3</p><p>Fixed in version 3.5.4 </p>
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-4373
The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina Particle Layer widget in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-35703 is likely a duplicate of this issue.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-4333
The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via several parameters in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
+ 10 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-34384
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.5.2 |
Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) |
Alta
8,8
|
< 3.5.2
|
3.5.2 |
2024-05-03 |
—
|
|
CVE-2024-3988
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.5.3 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.5.3
|
3.5.3 |
2024-04-24 |
—
|
|
CVE-2024-29935
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.5.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 3.5.1
|
3.5.1 |
2024-03-25 |
—
|
|
CVE-2021-24269
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.3.12 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.3.12
|
3.3.12 |
2021-04-13 |
—
|
|
—
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.3.12 |
— |
Desconocido
|
< 3.3.12
|
3.3.12 |
2021-04-13 |
—
|
|
—
|
Sina Extension for Elementor [sina-extension-for-elementor] < 2.2.1 |
— |
Desconocido
|
< 2.2.1
|
2.2.1 |
2019-06-25 |
—
|
|
CVE-2019-15839
|
Sina Extension for Elementor [sina-extension-for-elementor] < 2.2.1 |
Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) |
Alta
7,5
|
< 2.2.1
|
2.2.1 |
2019-06-19 |
—
|
|
CVE-2025-1517
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.6.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.6.1
|
3.6.1 |
0000-00-00 |
—
|
|
CVE-2025-6228
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.7.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 3.7.1
|
3.7.1 |
0000-00-00 |
—
|
|
CVE-2025-6229
|
Sina Extension for Elementor [sina-extension-for-elementor] < 3.7.1 |
— |
Desconocido
|
< 3.7.1
|
3.7.1 |
0000-00-00 |
—
|
CVE-2024-34384
The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.5.1. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-3988
The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina Fancy Text Widget in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-29935
Update the WordPress Sina Extension for Elementor plugin to the latest available version (at least 3.5.1).
Abu Hurayra discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Sina Extension for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.5.1.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2021-24269
The “Sina Extension for Elementor” WordPress Plugin before 3.3.12 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
The “Banner Slider” widget accepts a “title_tag” and a “subtitle_tag” parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a ‘save_builder’ request containing JavaScript in either of these parameters, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.
Additionally the following widgets appear to have similar vulnerabilities:
Sina Content Slider:title_tag,subtitle_tag parameters
Sina Particle Layer:title_tag parameter
Sina title:title_tag,subtitle_tag parameters
These vulnerabilities are nearly identical to the vulnerabilities we have recently disclosed in the main Elementor plugin: https://www.wordfence.com/blog/2021/03/cross-site-scripting-vulnerabilities-in-elementor-impact-over-7-million-sites/
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Sina Extension for Elementor [sina-extension-for-elementor] < 3.3.12
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress Sina Extension for Elementor plugin (versions <= 3.3.11).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Sina Extension for Elementor [sina-extension-for-elementor] < 2.2.1
Local File Inclusion (LFI) vulnerability found in WordPress Sina Extension For Elementor plugin (versions <= 2.2.0).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2019-15839
The Sina Extension for Elementor WordPress plugin was affected by a LFI security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
CVE-2025-1517
The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text, Countdown Widget, and Login Form shortcodes in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-6228
The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `Sina Posts`, `Sina Blog Post` and `Sina Table` widgets in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-6229
The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `Fancy Text Widget` And `Countdown Widget` DOM attributes in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Cómo solucionarlo
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas