Resources /
WordPress Plugins /
Dynamic Content For Elementor
PLUGIN SECURITY
Is Dynamic Content For Elementor safe?
Known vulnerabilities, PHP compatibility and safer alternatives for the Dynamic Content For Elementor WordPress plugin — checked against WP Clinic's local security database.
What this plugin does
- Slug:
dynamic-content-for-elementor
Maintenance status
Known vulnerabilities
2 known CVEs on file for Dynamic Content For Elementor.
Reported between 2020 and 2023.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-52150
|
Dynamic Content for Elementor [dynamic-content-for-elementor] < 2.12.5 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 2.12.5
|
2.12.5 |
2023-12-28 |
—
|
|
CVE-2020-26596
|
Dynamic Content for Elementor [dynamic-content-for-elementor] < 1.9.6 |
Improper Privilege Management |
High
8.8
|
< 1.9.6
|
1.9.6 |
2020-10-06 |
—
|
CVE-2023-52150
Update the WordPress Dynamic Content for Elementor plugin to the latest available version (at least 2.12.5).
Dave Jong (Patchstack) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Dynamic Content for Elementor Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 2.12.5.
Have additional information or questions about this entry? Get in touch.
Source:
Patchstack
CVE-2020-26596
The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.
Source:
CVE.org
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.