+ 33 more known vulnerabilities
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-13155
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.141 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 1.5.141
|
1.5.141 |
2025-02-19 |
—
|
|
CVE-2024-13153
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.136 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 1.5.136
|
1.5.136 |
2025-01-08 |
—
|
|
CVE-2024-10784
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.127 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 1.5.127
|
1.5.127 |
2024-12-11 |
—
|
|
CVE-2024-49271
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.122 |
Improper Neutralization of Script in Attributes of IMG Tags in a Web Page |
Critical
9.1
|
< 1.5.122
|
1.5.122 |
2024-10-14 |
—
|
|
CVE-2024-45454
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.122 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.1
|
< 1.5.122
|
1.5.122 |
2024-09-30 |
—
|
|
CVE-2024-6170
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 1.5.113
|
1.5.113 |
2024-07-08 |
—
|
|
CVE-2024-6169
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 1.5.113
|
1.5.113 |
2024-07-08 |
—
|
|
CVE-2024-6171
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113 |
Use of Less Trusted Source |
Medium
5.3
|
< 1.5.113
|
1.5.113 |
2024-07-08 |
—
|
|
CVE-2024-6166
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.113 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
8.8
|
< 1.5.113
|
1.5.113 |
2024-07-08 |
—
|
|
CVE-2024-35674
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.110 |
Missing Authorization |
Medium
4.3
|
< 1.5.110
|
1.5.110 |
2024-06-05 |
—
|
|
CVE-2024-5329
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.110 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
8.8
|
< 1.5.110
|
1.5.110 |
2024-06-05 |
—
|
|
CVE-2024-3190
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.108 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.6
|
< 1.5.108
|
1.5.108 |
2024-05-29 |
—
|
|
CVE-2023-6743
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.91 |
Improper Control of Generation of Code ('Code Injection') |
High
8.8
|
< 1.5.91
|
1.5.91 |
2024-05-28 |
—
|
|
CVE-2024-4779
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.108 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
8.8
|
< 1.5.108
|
1.5.108 |
2024-05-22 |
—
|
|
CVE-2024-3055
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.105 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
8.8
|
< 1.5.105
|
1.5.105 |
2024-05-10 |
—
|
|
CVE-2024-2662
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.103 |
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
High
7.2
|
< 1.5.103
|
1.5.103 |
2024-05-09 |
—
|
|
CVE-2024-3547
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.103 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 1.5.103
|
1.5.103 |
2024-05-09 |
—
|
|
CVE-2024-0367
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.97 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 1.5.97
|
1.5.97 |
2024-03-29 |
—
|
|
CVE-2024-29792
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.94 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.1
|
< 1.5.94
|
1.5.94 |
2024-03-25 |
—
|
|
CVE-2023-33999
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.75 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.1
|
< 1.5.75
|
1.5.75 |
2023-07-18 |
—
|
|
CVE-2023-31080
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.66 |
Missing Authorization |
High
8.3
|
< 1.5.66
|
1.5.66 |
2023-06-20 |
—
|
|
CVE-2023-31231
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.66 |
Unrestricted Upload of File with Dangerous Type |
Critical
9.9
|
< 1.5.66
|
1.5.66 |
2023-06-20 |
—
|
|
CVE-2023-3295
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.67 |
Unrestricted Upload of File with Dangerous Type |
High
8.8
|
< 1.5.67
|
1.5.67 |
2023-06-16 |
—
|
|
CVE-2023-31090
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.61 |
Unrestricted Upload of File with Dangerous Type |
Critical
9.9
|
< 1.5.61
|
1.5.61 |
2023-05-22 |
—
|
|
CVE-2023-33930
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.67 |
Unrestricted Upload of File with Dangerous Type |
Critical
9.1
|
< 1.5.67
|
1.5.67 |
2023-05-22 |
—
|
|
CVE-2022-47170
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.49 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.9
|
< 1.5.49
|
1.5.49 |
2023-01-27 |
—
|
|
—
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3 |
Missing Authorization |
Medium
6.3
|
< 1.5.3
|
1.5.3 |
2022-03-04 |
—
|
|
—
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3 |
— |
Unknown
|
< 1.5.3
|
1.5.3 |
2022-02-28 |
—
|
|
—
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3 |
— |
Unknown
|
< 1.5.3
|
1.5.3 |
2022-02-28 |
—
|
|
CVE-2025-1663
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.143 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 1.5.143
|
1.5.143 |
0000-00-00 |
—
|
|
CVE-2025-8603
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.149 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 1.5.149
|
1.5.149 |
0000-00-00 |
—
|
|
CVE-2026-2724
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 2.0.6 |
— |
Unknown
|
< 2.0.6
|
2.0.6 |
0000-00-00 |
—
|
|
—
|
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3 |
— |
Unknown
|
< 1.5.3
|
1.5.3 |
— |
—
|
CVE-2024-13155
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up to, and including, 1.5.140 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: Since the widget code isn't part of the code base, to apply the patch, the affected widget: Transparent Split Hero must be deleted and reinstalled manually.
Source:
CVE.org
CVE-2024-13153
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.135 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: Since the widget code isn't part of the code base, to apply the patch, the affected widgets: Image Tooltip, Notification, Simple Popup, Video Play Button, and Card Carousel, must be deleted and reinstalled manually.
Source:
CVE.org
CVE-2024-10784
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Tile Gallery' widget in all versions up to, and including, 1.5.126 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-49271
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.121 via the template engine. This is due to the plugin not properly restricting functions that can be called and passed to code execution functions. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server.
Source:
Wordfence
CVE-2024-45454
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.121 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Source:
Wordfence
CVE-2024-6170
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘email’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-6169
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above and granted plugin setting edit permissions by an administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
CVE.org
CVE-2024-6171
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.5.112 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass antispam functionality in the Form Builder widgets.
Source:
CVE.org
CVE-2024-6166
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions up to, and including, 1.5.112 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above and granted plugin setting edit permissions by an administrator, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Source:
CVE.org
CVE-2024-35674
<p>WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin <= 1.5.109 is vulnerable to Broken Access Control</p><p>Software: Unlimited Elements For Elementor (Free Widgets, Addons, Templates)</p><p>Link: https://wordpress.org/plugins/unlimited-elements-for-elementor/#developers</p><p>Affected Version <= 1.5.109</p><p>Fixed in version 1.5.110 </p>
Source:
Patchstack
CVE-2024-5329
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to blind SQL Injection via the ‘data[addonID]’ parameter in all versions up to, and including, 1.5.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Source:
CVE.org
CVE-2024-3190
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text field widget in all versions up to, and including, 1.5.107 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Please note that this vulnerability is different in that the issue stems from an external template. It appears that older version may also be patched due to this, however, we are choosing 1.5.108 as the patched version since that is the most recent version containing as known patch.
Source:
CVE.org
CVE-2023-6743
<p>WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin <= 1.5.89 is vulnerable to Remote Code Execution (RCE)</p><p>Software: Unlimited Elements For Elementor (Free Widgets, Addons, Templates)</p><p>Link: https://wordpress.org/plugins/unlimited-elements-for-elementor/#developers</p><p>Affected Version <= 1.5.89</p><p>Fixed in version 1.5.91 </p>
Source:
Patchstack
CVE-2024-4779
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injection via the ‘data[post_ids][0]’ parameter in all versions up to, and including, 1.5.107 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Source:
CVE.org
CVE-2024-3055
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Source:
CVE.org
CVE-2024-2662
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command injection in all versions up to, and including, 1.5.102. This is due to insufficient filtering of template attributes during the creation of HTML for custom widgets This makes it possible for authenticated attackers, with administrator-level access and above, to execute arbitrary commands on the server.
Source:
CVE.org
CVE-2024-3547
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_connect_error' parameter in all versions up to, and including, 1.5.102 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Source:
CVE.org
CVE-2024-0367
Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 1.5.97).
Webbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.5.97.
Have additional information or questions about this entry? Get in touch.
Source:
Patchstack
CVE-2024-29792
Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 1.5.94).
Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.5.94.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Source:
Patchstack
CVE-2023-33999
Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 1.5.75).
Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.5.75.
Source:
Patchstack
CVE-2023-31080
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the extensive functions throughout the plugin in versions up to, and including, 1.5.65. This makes it possible for authenticated attackers, with contributor-level access and above, to perform a plethora of unauthorized actions such as updating/ deleting/modfying addons and modifying various settings.
Source:
Wordfence
CVE-2023-31231
Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 1.5.66).
Rafie Muhammad (Patchstack) discovered and reported this Arbitrary File Upload vulnerability in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 1.5.66.
Source:
Patchstack
CVE-2023-3295
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authenticated attackers, with contributor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The issue was partially patched in version 1.5.66 and fully patched in 1.5.67. CVE-2023-31231 appears to be a duplicate of this issue.
Source:
CVE.org
CVE-2023-31090
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files within zip files in the File Manager functionality in versions up to, and including, 1.5.60 . This makes it possible for authenticated attackers, with contributor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Source:
Wordfence
CVE-2023-33930
Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 1.5.67).
Achref Ben Thameur discovered and reported this Bypass Vulnerability vulnerability in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has been fixed in version 1.5.67.
Source:
Patchstack
CVE-2022-47170
Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 1.5.49).
Muhammad Daffa discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.5.49.
Source:
Patchstack
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Source:
Wordfence
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)" plugin (versions < 1.5.3).
Source:
Patchstack
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3
Sensitive Information Disclosure vulnerability discovered in WordPress "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)" plugin (versions < 1.5.3).
Source:
Patchstack
CVE-2025-1663
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.142 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
Wordfence
CVE-2025-8603
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.5.148 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source:
Wordfence
CVE-2026-2724
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up to, and including, 2.0.5. This is due to insufficient input sanitization and output escaping on form submission data displayed in the admin Form Entries Trash view. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views the trashed form entries.
Source:
Wordfence
Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.3
The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a CSRF attack.
Source:
WPScan
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.