_______________________________________________________________
__ _______ _____
\ \ / / __ \ / ____|
\ \ /\ / /| |__) | (___ ___ __ _ _ __ ®
\ \/ \/ / | ___/ \___ \ / __|/ _` | '_ \
\ /\ / | | ____) | (__| (_| | | | |
\/ \/ |_| |_____/ \___|\__,_|_| |_|
WordPress Security Scanner
Version 4.0.0
An Automattic endeavor
https://automattic.com
_______________________________________________________________
[i] Updating the Database ...
[i] Update completed.
[+] URL: https://pzsz.gov.rs/ [109.111.253.121]
[+] Started: Sat Jun 6 12:35:21 2026
Interesting Finding(s):
[+] Headers
| Interesting Entry: Server: Apache
| Found By: Headers (Passive Detection)
| Confidence: 100%
[+] XML-RPC seems to be enabled: https://pzsz.gov.rs/xmlrpc.php
| Found By: Link Tag (Passive Detection)
| Confidence: 30%
| References:
| - http://codex.wordpress.org/XML-RPC_Pingback_API
| - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner/
| - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos/
| - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login/
| - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access/
[+] WordPress version 7.0 identified (Latest, released on 2026-05-20).
| Found By: Rss Generator (Passive Detection)
| - https://pzsz.gov.rs/feed/, https://wordpress.org/?v=7.0
| Confirmed By: Rss Generator (Passive Detection)
| - https://pzsz.gov.rs/comments/feed/, https://wordpress.org/?v=7.0
[+] WordPress theme in use: hello-theme-child-master
| Location: https://pzsz.gov.rs/wp-content/themes/hello-theme-child-master/
| Style URL: https://pzsz.gov.rs/wp-content/themes/hello-theme-child-master/style.css?ver=2.0.0
| Style Name: Hello Elementor Child
| Style URI: https://github.com/elementor/hello-theme-child/
| Description: Hello Elementor Child is a child theme of Hello Elementor, created by Elementor team...
| Author: Elementor Team
| Author URI: https://elementor.com/
|
| Found By: Css Style In Homepage (Passive Detection)
| Confirmed By: Css Style In 404 Page (Passive Detection)
|
| Version: 2.0.0 (80% confidence)
| Found By: Style (Passive Detection)
| - https://pzsz.gov.rs/wp-content/themes/hello-theme-child-master/style.css?ver=2.0.0, Match: 'Version: 2.0.0'
[+] *
| Location: https://pzsz.gov.rs/wp-content/plugins/*/
|
| Found By: Urls In Homepage (Passive Detection)
|
| The version could not be determined.
[+] 3d-flipbook-dflip-lite
| Location: https://pzsz.gov.rs/wp-content/plugins/3d-flipbook-dflip-lite/
| Latest Version: 2.4.30 (up to date)
| Last Updated: 2026-06-02 6:21am GMT (4 days ago, per WordPress.org)
| Active Installs: 200,000 (per WordPress.org)
|
| Found By: Urls In Homepage (Passive Detection)
|
| [!] 1 vulnerability identified:
|
| [!] Title: DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer <= 2.4.28 - Missing Authorization
| UUID: 50fce13a-28c6-411d-a534-9cf7e8893dea
| References:
| - https://wpscan.com/vulnerability/50fce13a-28c6-411d-a534-9cf7e8893dea
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-49047
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/b3146b41-27d5-465d-a9ec-af4c50a0d612
|
| Version: 2.4.30 (20% confidence)
| Found By: Query Parameter (Passive Detection)
| - https://pzsz.gov.rs/wp-content/plugins/3d-flipbook-dflip-lite/assets/css/dflip.min.css?ver=2.4.30
| - https://pzsz.gov.rs/wp-content/plugins/3d-flipbook-dflip-lite/assets/js/dflip.min.js?ver=2.4.30
[+] document-gallery
| Location: https://pzsz.gov.rs/wp-content/plugins/document-gallery/
| Latest Version: 5.1.0
| Last Updated: 2025-12-09 1:05am GMT (5 months ago, per WordPress.org)
| Active Installs: 8,000 (per WordPress.org)
|
| Found By: Urls In Homepage (Passive Detection)
|
| The version could not be determined.
[+] elementor
| Location: https://pzsz.gov.rs/wp-content/plugins/elementor/
| Latest Version: 4.1.1 (up to date)
| Last Updated: 2026-05-27 11:27am GMT (9 days ago, per WordPress.org)
| Active Installs: 10,000,000 (per WordPress.org)
|
| Found By: Urls In Homepage (Passive Detection)
|
| Version: 4.1.1 (20% confidence)
| Found By: Query Parameter (Passive Detection)
| - https://pzsz.gov.rs/wp-content/plugins/elementor/assets/css/frontend.min.css?ver=4.1.1
| - https://pzsz.gov.rs/wp-content/plugins/elementor/assets/js/frontend.min.js?ver=4.1.1
[+] elementor-pro
| Location: https://pzsz.gov.rs/wp-content/plugins/elementor-pro/
|
| Found By: Urls In Homepage (Passive Detection)
|
| Version: 3.33.1 (30% confidence)
| Found By: Query Parameter (Passive Detection)
| - https://pzsz.gov.rs/wp-content/plugins/elementor-pro/assets/lib/sticky/jquery.sticky.min.js?ver=3.33.1
| - https://pzsz.gov.rs/wp-content/plugins/elementor-pro/assets/js/webpack-pro.runtime.min.js?ver=3.33.1
| - https://pzsz.gov.rs/wp-content/plugins/elementor-pro/assets/js/frontend.min.js?ver=3.33.1
[+] embedpress
| Location: https://pzsz.gov.rs/wp-content/plugins/embedpress/
| Latest Version: 4.5.4
| Last Updated: 2026-05-25 6:08am GMT (12 days ago, per WordPress.org)
| Active Installs: 100,000 (per WordPress.org)
|
| Found By: Urls In Homepage (Passive Detection)
|
| [!] 29 vulnerabilities identified:
|
| [!] Title: EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor < 3.8.0 - Sensitive Data Disclosure
| UUID: 082ae437-0f1c-4e63-9e23-4bf0ec732985
| Fixed in: 3.8.0
| References:
| - https://wpscan.com/vulnerability/082ae437-0f1c-4e63-9e23-4bf0ec732985
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3371
|
| [!] Title: Freemius SDK < 2.5.10 - Reflected Cross-Site Scripting
| UUID: 39d1f22f-ea34-4d94-9dc2-12661cf69d36
| Fixed in: 2.0.3
| References:
| - https://wpscan.com/vulnerability/39d1f22f-ea34-4d94-9dc2-12661cf69d36
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33999
|
| [!] Title: EmbedPress < 3.8.3 - Contributor+ Stored Cross-Site Scripting via Shortcode
| UUID: 25d0d190-0748-4518-ad83-ba6a0f9d1319
| Fixed in: 3.8.3
| References:
| - https://wpscan.com/vulnerability/25d0d190-0748-4518-ad83-ba6a0f9d1319
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4283
| - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/embedpress/embedpress-382-authenticated-contributor-stored-cross-site-scripting-via-shortcode
|
| [!] Title: EmbedPress < 3.8.3 - Subscriber+ Plugin Settings Delete
| UUID: 8e5b3e67-7640-48a0-b1e0-c118eb9de8d8
| Fixed in: 3.8.3
| References:
| - https://wpscan.com/vulnerability/8e5b3e67-7640-48a0-b1e0-c118eb9de8d8
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4282
| - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/embedpress/embedpress-382-missing-authorization-to-authenticated-subscriber-plugin-settings-delete-via-admin-post-remove-and-remove-private-data
|
| [!] Title: EmbedPress < 3.9.2 - Reflected XSS
| UUID: cf323f72-8374-40fe-9e2e-810e46de1ec8
| Fixed in: 3.9.2
| References:
| - https://wpscan.com/vulnerability/cf323f72-8374-40fe-9e2e-810e46de1ec8
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5750
|
| [!] Title: EmbedPress < 3.9.2 - Reflected XSS
| UUID: 3931daac-3899-4169-8625-4c95fd2adafc
| Fixed in: 3.9.2
| References:
| - https://wpscan.com/vulnerability/3931daac-3899-4169-8625-4c95fd2adafc
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5749
|
| [!] Title: EmbedPress < 3.8.4 - Cross-Site Request Forgery
| UUID: 7c269cdb-98f4-4207-a6ca-3f4e09c96630
| Fixed in: 3.8.4
| References:
| - https://wpscan.com/vulnerability/7c269cdb-98f4-4207-a6ca-3f4e09c96630
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/36ba23ea-7e79-4048-8030-7ed6b2ff45a6
|
| [!] Title: EmbedPress < 3.9.6 - Contributor+ Stored XSS
| UUID: 643d3453-e3a4-40ee-953f-c8149373ac59
| Fixed in: 3.9.6
| References:
| - https://wpscan.com/vulnerability/643d3453-e3a4-40ee-953f-c8149373ac59
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6986
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/ceae0115-268c-401b-876b-3477d10c10e6
|
| [!] Title: EmbedPress < 3.9.5 - Missing Authorization
| UUID: 3436bbc5-c7b6-4b3b-97fc-786ba66748e1
| Fixed in: 3.9.5
| References:
| - https://wpscan.com/vulnerability/3436bbc5-c7b6-4b3b-97fc-786ba66748e1
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/a7cf1c70-9778-4b50-b494-d0b1d0277b35
|
| [!] Title: EmbedPress < 3.9.9 - Authenticated(Contributor+) Stored Cross-Site Scripting via Google Calendar Widget Link
| UUID: 909d265a-78a8-4222-b244-7b49d2da24e8
| Fixed in: 3.9.9
| References:
| - https://wpscan.com/vulnerability/909d265a-78a8-4222-b244-7b49d2da24e8
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1425
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/4d4568c8-f58c-4c37-94b9-6154e5c46928
|
| [!] Title: EmbedPress < 3.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
| UUID: bebfee16-eb15-41ba-826d-d37f7ced135d
| Fixed in: 3.9.9
| References:
| - https://wpscan.com/vulnerability/bebfee16-eb15-41ba-826d-d37f7ced135d
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1349
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/631d200f-7b0b-4105-b91e-030af459ba99
|
| [!] Title: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 3.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget
| UUID: a4a2eae0-473c-4d48-97f8-dbd54b153341
| Fixed in: 3.9.11
| References:
| - https://wpscan.com/vulnerability/a4a2eae0-473c-4d48-97f8-dbd54b153341
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2128
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/6189368d-5925-4c84-9f0f-694b9ebcd45e
|
| [!] Title: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 3.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Wistia Block
| UUID: 8896625b-ec99-461f-86c6-c48798287177
| Fixed in: 3.9.11
| References:
| - https://wpscan.com/vulnerability/8896625b-ec99-461f-86c6-c48798287177
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1802
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/48511d1a-2fd5-4be4-8409-e99d4aadcdfe
|
| [!] Title: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 3.9.13 - Authenticated (Contributor+) Stored Cross-site Scripting via 'embedpress_doc_custom_color'
| UUID: 1979b942-3a63-4dde-abbb-1b9e01f93720
| Fixed in: 3.9.13
| References:
| - https://wpscan.com/vulnerability/1979b942-3a63-4dde-abbb-1b9e01f93720
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2688
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/c5b67927-5993-4e21-af52-8ebe7fee48ab
|
| [!] Title: EmbedPress < 3.9.13 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Attribute
| UUID: 4a2e6bca-2108-465f-ac4d-9376e2834cf8
| Fixed in: 3.9.13
| References:
| - https://wpscan.com/vulnerability/4a2e6bca-2108-465f-ac4d-9376e2834cf8
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2468
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/ce3f1310-4d2e-45aa-a3ee-3972a6a31c2e
|
| [!] Title: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 3.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
| UUID: b937c331-3856-4ad2-bebe-cb59fcc06a34
| Fixed in: 3.9.15
| References:
| - https://wpscan.com/vulnerability/b937c331-3856-4ad2-bebe-cb59fcc06a34
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3244
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/778d8443-fc0f-4e97-8460-e5ceee8b62a1
|
| [!] Title: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 3.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Block
| UUID: 136076e8-457e-457b-be41-45e61e7439f7
| Fixed in: 3.9.15
| References:
| - https://wpscan.com/vulnerability/136076e8-457e-457b-be41-45e61e7439f7
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3245
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/a427c798-f546-4ca1-98ab-32b433ee5b59
|
| [!] Title: EmbedPress < 3.9.12 - Missing Authorization
| UUID: 640d7183-9e89-40bc-ab7e-14271ec78475
| Fixed in: 3.9.12
| References:
| - https://wpscan.com/vulnerability/640d7183-9e89-40bc-ab7e-14271ec78475
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31274
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/0ce738ee-bbb6-462a-aeae-0523200e320f
|
| [!] Title: EmbedPress < 3.9.9 - Missing Authorization via handle_calendly_data
| UUID: bce8f1ef-f794-4857-a284-0aa864a36946
| Fixed in: 3.9.9
| References:
| - https://wpscan.com/vulnerability/bce8f1ef-f794-4857-a284-0aa864a36946
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31284
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/be33065e-dae8-44cf-9f8a-f9971f2743ff
|
| [!] Title: EmbedPress Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 3.9.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
| UUID: d621d992-84c5-48a6-9a86-a6abf57c332e
| Fixed in: 3.9.17
| References:
| - https://wpscan.com/vulnerability/d621d992-84c5-48a6-9a86-a6abf57c332e
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4316
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/2af03168-9344-4db0-9b69-2ad1fdb6d472
|
| [!] Title: EmbedPress < 3.9.13 - Contributor+ PDF Block Embedding
| UUID: ce23ec26-9c61-4546-a179-9fe87019cee4
| Fixed in: 3.9.13
| References:
| - https://wpscan.com/vulnerability/ce23ec26-9c61-4546-a179-9fe87019cee4
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1803
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/175e08ce-aec2-427a-90e0-f955711d58b2
|
| [!] Title: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget
| UUID: 31dbe99a-cbea-4d47-8e4c-34c26603e87c
| Fixed in: 4.0.2
| References:
| - https://wpscan.com/vulnerability/31dbe99a-cbea-4d47-8e4c-34c26603e87c
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5571
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/7becdab6-f952-4649-8cea-4efadf841619
|
| [!] Title: EmbedPress < 3.9.11 - Authenticated(Contributor+) Stored Cross-Site Scripting via PDF Widget URL
| UUID: d5a25afe-f6d4-4ee0-bfbc-1396088aba22
| Fixed in: 3.9.11
| References:
| - https://wpscan.com/vulnerability/d5a25afe-f6d4-4ee0-bfbc-1396088aba22
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1565
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/caa97ae8-40a8-4ca1-820b-83675c053bfc
|
| [!] Title: EmbedPress < 4.0.5 - Missing Authorization
| UUID: 3300fd33-de42-4ab3-8674-81594b1f6444
| Fixed in: 4.0.5
| References:
| - https://wpscan.com/vulnerability/3300fd33-de42-4ab3-8674-81594b1f6444
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38707
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/f507cec5-d66c-4cb0-8c35-a985aaee1283
|
| [!] Title: EmbedPress < 4.0.10 - Unauthenticated Local File Inclusion
| UUID: f35019b8-eeec-46af-a65b-829f663401a4
| Fixed in: 4.0.10
| References:
| - https://wpscan.com/vulnerability/f35019b8-eeec-46af-a65b-829f663401a4
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-43328
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/21a1b117-945f-49bc-9ea1-313afa93bf32
|
| [!] Title: EmbedPress < 4.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
| UUID: faeab079-6002-426c-94f9-f1cc4b761cc9
| Fixed in: 4.0.9
| References:
| - https://wpscan.com/vulnerability/faeab079-6002-426c-94f9-f1cc4b761cc9
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-43936
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/31f8bd62-32de-468c-9bed-e03374cb595c
|
| [!] Title: EmbedPress < 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
| UUID: d758bc36-654f-416d-8938-00f091e81501
| Fixed in: 4.1.0
| References:
| - https://wpscan.com/vulnerability/d758bc36-654f-416d-8938-00f091e81501
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50461
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/b6851bb9-f15a-4d37-8a15-f4677bd5d62e
|
| [!] Title: EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor < 4.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'provider_name'
| UUID: 91529f39-5792-4fcf-8eac-09437299ea06
| Fixed in: 4.1.4
| References:
| - https://wpscan.com/vulnerability/91529f39-5792-4fcf-8eac-09437299ea06
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11203
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/167dedfa-36cc-4b01-8ea4-8eda8742953c
|
| [!] Title: EmbedPress < 4.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' Attribute
| UUID: 189be8b7-70c4-4936-8ab0-2754a9a3dd55
| Fixed in: 4.5.4
| References:
| - https://wpscan.com/vulnerability/189be8b7-70c4-4936-8ab0-2754a9a3dd55
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7796
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/a0b5b6bc-5f4f-4cf8-987e-b20e8354d863
|
| The version could not be determined.
[+] header-footer-elementor
| Location: https://pzsz.gov.rs/wp-content/plugins/header-footer-elementor/
| Latest Version: 2.8.8
| Last Updated: 2026-05-27 10:52am GMT (9 days ago, per WordPress.org)
| Active Installs: 2,000,000 (per WordPress.org)
|
| Found By: Urls In Homepage (Passive Detection)
|
| [!] 12 vulnerabilities identified:
|
| [!] Title: Elementor - Header, Footer & Blocks Template < 1.5.8 - Contributor+ Stored XSS
| UUID: a9412fed-aed3-4931-a504-1a86f876892e
| Fixed in: 1.5.8
| References:
| - https://wpscan.com/vulnerability/a9412fed-aed3-4931-a504-1a86f876892e
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24256
| - https://www.wordfence.com/blog/2021/04/recent-patches-rock-the-elementor-ecosystem/
|
| [!] Title: Elementor Header & Footer Builder < 1.6.25 - Contributor+ Stored Cross-Site Scripting
| UUID: 684e290a-1ebe-41eb-8ff7-254162391ecd
| Fixed in: 1.6.25
| References:
| - https://wpscan.com/vulnerability/684e290a-1ebe-41eb-8ff7-254162391ecd
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1237
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/82644c46-205b-4005-bba8-6b3e45769639
|
| [!] Title: Elementor Header & Footer Builder < 1.6.29 - Authenticated (Contributor+) Stored Cross-Site Scripting
| UUID: 2a0d3d1f-62f4-44e2-90a4-d3fa41f01650
| Fixed in: 1.6.29
| References:
| - https://wpscan.com/vulnerability/2a0d3d1f-62f4-44e2-90a4-d3fa41f01650
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4634
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/f44bb823-bbf3-413b-82b5-a351609270bf
|
| [!] Title: Elementor Header & Footer Builder < 1.6.27 - Authenticated (Author+) HTML Injection
| UUID: a262227b-6c2b-4093-9af1-14fcb7569f24
| Fixed in: 1.6.27
| References:
| - https://wpscan.com/vulnerability/a262227b-6c2b-4093-9af1-14fcb7569f24
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2619
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/689eb95b-2f72-4aa4-9f21-6ae186346061
|
| [!] Title: Elementor Header & Footer Builder < 1.6.26.1 - Contributor+ Stored XSS
| UUID: aa28669a-3c64-4e05-beb7-da41701050a5
| Fixed in: 1.6.26.1
| References:
| - https://wpscan.com/vulnerability/aa28669a-3c64-4e05-beb7-da41701050a5
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2618
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/a780ce1b-0758-42ef-88e7-ff8d921eca6e
|
| [!] Title: Elementor Header & Footer Builder < 1.6.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Title Widget
| UUID: a89bb975-5731-4a69-98fe-5888e6ffb4a5
| Fixed in: 1.6.36
| References:
| - https://wpscan.com/vulnerability/a89bb975-5731-4a69-98fe-5888e6ffb4a5
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5757
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/b5ab022c-c16c-488b-b004-a7351f8fa3d3
|
| [!] Title: Elementor – Header, Footer & Blocks Template < 1.6.36 - Authenticated (Contributor+) Stored Cross-Site Scripting
| UUID: c5a24410-a737-49bc-be58-a0403f5e8add
| Fixed in: 1.6.36
| References:
| - https://wpscan.com/vulnerability/c5a24410-a737-49bc-be58-a0403f5e8add
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33933
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/8c27fc2c-b515-4314-908d-435a4167ee99
|
| [!] Title: Elementor Header & Footer Builder < 1.6.44 - Authenticated (Contributor+) Information Disclosure via Shortcode
| UUID: 85f19e03-9939-4f9a-8064-36103ed6dd62
| Fixed in: 1.6.44
| References:
| - https://wpscan.com/vulnerability/85f19e03-9939-4f9a-8064-36103ed6dd62
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-10050
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/662f6ae2-2047-4bbf-b4a6-2d536051e389
|
| [!] Title: Elementor Header & Footer Builder < 1.6.46 - Author+ Stored XSS via SVG File Upload
| UUID: 7241192a-765e-40da-9e91-ca3bafaeba12
| Fixed in: 1.6.46
| References:
| - https://wpscan.com/vulnerability/7241192a-765e-40da-9e91-ca3bafaeba12
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-10325
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/7773fd3a-2417-415e-97b0-735e99e62097
|
| [!] Title: Elementor Header & Footer Builder < 1.6.47 - Contributor+ Stored XSS via Page Title Widget
| UUID: 00d77ab0-981c-4f30-85e1-1db21b070f91
| Fixed in: 1.6.47
| References:
| - https://wpscan.com/vulnerability/00d77ab0-981c-4f30-85e1-1db21b070f91
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11230
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/0d82c866-5b35-414e-bd72-30530930d5d8
|
| [!] Title: Ultimate Addons for Elementor < 2.4.7 - Subscriber+ Limited Settings Update
| UUID: 0c73756d-a808-4678-8918-f402037779d9
| Fixed in: 2.4.7
| References:
| - https://wpscan.com/vulnerability/0c73756d-a808-4678-8918-f402037779d9
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8488
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/a4b847b5-9deb-41c4-b976-725249e0098e
|
| [!] Title: Ultimate Addons for Elementor Lite < 2.5.0 - Author+ Stored XSS
| UUID: 4332d49b-d58c-4728-afab-6757ff9e43ee
| Fixed in: 2.5.0
| References:
| - https://wpscan.com/vulnerability/4332d49b-d58c-4728-afab-6757ff9e43ee
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-9703
|
| The version could not be determined.
[+] jeg-elementor-kit
| Location: https://pzsz.gov.rs/wp-content/plugins/jeg-elementor-kit/
| Latest Version: 3.2.2
| Last Updated: 2026-06-02 9:04am GMT (4 days ago, per WordPress.org)
| Active Installs: 300,000 (per WordPress.org)
|
| Found By: Urls In Homepage (Passive Detection)
|
| [!] 18 vulnerabilities identified:
|
| [!] Title: Jeg Elementor Kit < 2.5.7 - Subscriber+ Authorization Bypass
| UUID: 9cfd2d4a-d144-4203-b5f6-196e2dcdbca5
| Fixed in: 2.5.7
| References:
| - https://wpscan.com/vulnerability/9cfd2d4a-d144-4203-b5f6-196e2dcdbca5
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3794
|
| [!] Title: Jeg Elementor Kit < 2.5.7 - Unauthenticated Settings Update
| UUID: c431bd21-d2dc-4edc-a5e0-a8e0bdd6d069
| Fixed in: 2.5.7
| References:
| - https://wpscan.com/vulnerability/c431bd21-d2dc-4edc-a5e0-a8e0bdd6d069
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3805
|
| [!] Title: Jeg Elementor Kit < 2.6.3 - Contributor+ Stored Cross-Site Scripting
| UUID: ec997f21-3721-4dd8-ae0e-0645f8bca240
| Fixed in: 2.6.3
| References:
| - https://wpscan.com/vulnerability/ec997f21-3721-4dd8-ae0e-0645f8bca240
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1326
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/d108cb36-c072-483e-9746-15b8e7a880c3
|
| [!] Title: Jeg Elementor Kit < 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial
| UUID: 4e51cecb-0156-4272-9a4a-c37cfe76ffc7
| Fixed in: 2.6.4
| References:
| - https://wpscan.com/vulnerability/4e51cecb-0156-4272-9a4a-c37cfe76ffc7
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3162
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/d54c7623-25af-4bf1-a6e0-9022ec26f391
|
| [!] Title: Jeg Elementor Kit < 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Box
| UUID: a5581897-9384-4de1-8193-f0099e599afd
| Fixed in: 2.6.4
| References:
| - https://wpscan.com/vulnerability/a5581897-9384-4de1-8193-f0099e599afd
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1327
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/34a42180-9d08-4049-8da8-27ee1f64600a
|
| [!] Title: Jeg Elementor Kit < 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Banner
| UUID: b28a035f-c40a-42f1-a325-ccc5b268ac83
| Fixed in: 2.6.5
| References:
| - https://wpscan.com/vulnerability/b28a035f-c40a-42f1-a325-ccc5b268ac83
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3819
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/46868a11-0c82-4bd3-82b5-9a19a5a0cef1
|
| [!] Title: Jeg Elementor Kit < 2.6.5 - Contributor+ Stored XSS via Countdown Widget
| UUID: 221e015c-ba3f-462a-9155-23da6e6fa7f1
| Fixed in: 2.6.5
| References:
| - https://wpscan.com/vulnerability/221e015c-ba3f-462a-9155-23da6e6fa7f1
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3161
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/48a13fb7-bf1a-4bf2-ac3b-3b5a75fec616
|
| [!] Title: Jeg Elementor Kit < 2.6.5 - Contributor+ Stored XSS via Elementor Widget URL Custom Attributes
| UUID: c8717b6e-2702-4957-b15f-b025c94b4d19
| Fixed in: 2.6.5
| References:
| - https://wpscan.com/vulnerability/c8717b6e-2702-4957-b15f-b025c94b4d19
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0334
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/950e9042-1364-4200-8f57-171346075764
|
| [!] Title: Jeg Elementor Kit < 2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Tabs and JKit - Accordion Widgets
| UUID: 5cafd16a-eb8f-40f7-9944-0c64402bf66f
| Fixed in: 2.6.6
| References:
| - https://wpscan.com/vulnerability/5cafd16a-eb8f-40f7-9944-0c64402bf66f
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4479
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/c6048ba9-671f-4729-9618-d7a0556a31e6
|
| [!] Title: Jeg Elementor Kit < 2.6.8 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File
| UUID: a401aef4-3486-4e55-83b8-1dbb01d4f6df
| Fixed in: 2.6.8
| References:
| - https://wpscan.com/vulnerability/a401aef4-3486-4e55-83b8-1dbb01d4f6df
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6804
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/5491ff65-9060-4b0b-a31d-7b95ea581310
|
| [!] Title: Jeg Elementor Kit < 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
| UUID: 28ba86f5-7b53-42e9-9a5d-36cdd7dcfa59
| Fixed in: 2.6.9
| References:
| - https://wpscan.com/vulnerability/28ba86f5-7b53-42e9-9a5d-36cdd7dcfa59
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-47390
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/5b624e9b-d21e-43d2-83ad-7760ed63a75c
|
| [!] Title: Jeg Elementor Kit < 2.6.10 - Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template
| UUID: 2f089646-e285-4a09-aecc-5cb8fe100edc
| Fixed in: 2.6.10
| References:
| - https://wpscan.com/vulnerability/2f089646-e285-4a09-aecc-5cb8fe100edc
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8899
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/4efc9c47-321a-4635-943f-785ffc34d851
|
| [!] Title: Jeg Elementor Kit < 2.6.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Countdown Widget
| UUID: 1be116a3-1028-4b6c-ad8c-81ec1a1c993d
| Fixed in: 2.6.10
| References:
| - https://wpscan.com/vulnerability/1be116a3-1028-4b6c-ad8c-81ec1a1c993d
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-10308
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/98aed079-672c-43bb-a5eb-faf8ffc04b71
|
| [!] Title: Jeg Elementor Kit < 2.6.12 - Authenticated (Contributor+) Sensitive Information Exposure via Countdown and Off-Canvas
| UUID: 2461a3f3-f31c-456a-b491-8db88b25a8f7
| Fixed in: 2.6.12
| References:
| - https://wpscan.com/vulnerability/2461a3f3-f31c-456a-b491-8db88b25a8f7
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-13217
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/2136cad8-6b0b-4458-a357-6e98f1ac3e0b
|
| [!] Title: Jeg Elementor Kit < 2.6.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Button and Countdown Widgets
| UUID: 70d12b64-ba42-4def-aa24-8c6d9897d734
| Fixed in: 2.6.13
| References:
| - https://wpscan.com/vulnerability/70d12b64-ba42-4def-aa24-8c6d9897d734
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-2944
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/7baa8cca-96a5-4d6b-86d5-53cd1a4675cf
|
| [!] Title: Jeg Elementor Kit < 2.7.0 - Author+ Stored XSS
| UUID: cef78a77-c66d-4d62-8d49-140ca2d04d5b
| Fixed in: 2.7.0
| References:
| - https://wpscan.com/vulnerability/cef78a77-c66d-4d62-8d49-140ca2d04d5b
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-9978
|
| [!] Title: Jeg Elementor Kit < 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
| UUID: ba1b4d9c-ca12-4e2d-ae8b-8c3c27c9e87c
| Fixed in: 3.0.2
| References:
| - https://wpscan.com/vulnerability/ba1b4d9c-ca12-4e2d-ae8b-8c3c27c9e87c
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-14275
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/8fcb4047-5173-4d10-a4bb-72f1919b9203
|
| [!] Title: Jeg Kit for Elementor < 3.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_content_number_prefix' Shortcode Attribute
| UUID: dd087275-e61d-45b3-aaa9-647593d31c38
| Fixed in: 3.1.1
| References:
| - https://wpscan.com/vulnerability/dd087275-e61d-45b3-aaa9-647593d31c38
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6916
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/5000c86b-b535-48de-b3e0-0dd0d2fd9b1e
|
| The version could not be determined.
[+] quick-event-manager
| Location: https://pzsz.gov.rs/wp-content/plugins/quick-event-manager/
| Latest Version: 9.17
| Last Updated: 2025-10-28 6:25pm GMT (7 months ago, per WordPress.org)
| Active Installs: 1,000 (per WordPress.org)
|
| Found By: Urls In Homepage (Passive Detection)
|
| [!] 6 vulnerabilities identified:
|
| [!] Title: Unauthorised AJAX Calls via Freemius
| UUID: 6dae6dca-7474-4008-9fe5-4c62b9f12d0a
| Fixed in: 9.2.17
| Reference: https://wpscan.com/vulnerability/6dae6dca-7474-4008-9fe5-4c62b9f12d0a
|
| [!] Title: Quick Event Manager < 9.7.5 - Reflected Cross-Site
| UUID: 49178a9d-0500-4e3e-8ea1-6cd4eeda2a4e
| Fixed in: 9.7.5
| References:
| - https://wpscan.com/vulnerability/49178a9d-0500-4e3e-8ea1-6cd4eeda2a4e
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23491
| - https://www.tenable.com/security/research/tra-2023-3
|
| [!] Title: Quick Event Manager < 9.7.5 - Registration Deletion/Update via CSRF
| UUID: 1f8b493d-04c2-4761-b2e9-728379a8a822
| Fixed in: 9.7.5
| References:
| - https://wpscan.com/vulnerability/1f8b493d-04c2-4761-b2e9-728379a8a822
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23974
|
| [!] Title: Quick Event Manager < 9.6.5 - Admin+ Stored XSS
| UUID: 55c255fb-82be-4af0-8edb-97d067e4cac5
| Fixed in: 9.6.5
| References:
| - https://wpscan.com/vulnerability/55c255fb-82be-4af0-8edb-97d067e4cac5
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-46863
|
| [!] Title: Quick Event Manager < 9.7.5 - Unauthenticated Stored XSS
| UUID: 64c677b2-dc35-4b88-8390-0977e621b90c
| Fixed in: 9.7.5
| References:
| - https://wpscan.com/vulnerability/64c677b2-dc35-4b88-8390-0977e621b90c
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23979
|
| [!] Title: Freemius SDK < 2.5.10 - Reflected Cross-Site Scripting
| UUID: 39d1f22f-ea34-4d94-9dc2-12661cf69d36
| Fixed in: 9.8.5.3
| References:
| - https://wpscan.com/vulnerability/39d1f22f-ea34-4d94-9dc2-12661cf69d36
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33999
|
| The version could not be determined.
[+] wordpress-seo
| Location: https://pzsz.gov.rs/wp-content/plugins/wordpress-seo/
| Latest Version: 27.7 (up to date)
| Last Updated: 2026-05-27 9:21am GMT (10 days ago, per WordPress.org)
| Active Installs: 10,000,000 (per WordPress.org)
|
| Found By: Comment (Passive Detection)
|
| Version: 27.7 (60% confidence)
| Found By: Comment (Passive Detection)
| - https://pzsz.gov.rs/, Match: 'optimized with the Yoast SEO plugin v27.7 -'
[i] 10 plugin(s) Identified.
[+] hello-elementor
| Location: https://pzsz.gov.rs/wp-content/themes/hello-elementor/
| Last Updated: 2026-05-19 10:00pm GMT (17 days ago, per WordPress.org)
| Active Installs: 1,000,000 (per WordPress.org)
| [!] The version is out of date, the latest version is 3.4.9
| Style URL: https://pzsz.gov.rs/wp-content/themes/hello-elementor/style.css
| Style Name: Hello Elementor
| Style URI: https://elementor.com/hello-theme/?utm_source=wp-themes&utm_campaign=theme-uri&utm_medium=wp-dash
| Description: Hello Elementor is a lightweight and minimalist WordPress theme that was built specifically to work ...
| Author: Elementor Team
| Author URI: https://elementor.com/?utm_source=wp-themes&utm_campaign=author-uri&utm_medium=wp-dash
|
| Found By: Urls In Homepage (Passive Detection)
|
| Version: 3.4.7 (80% confidence)
| Found By: Style (Passive Detection)
| - https://pzsz.gov.rs/wp-content/themes/hello-elementor/style.css, Match: 'Version: 3.4.7'
[+] hello-theme-child-master
| Location: https://pzsz.gov.rs/wp-content/themes/hello-theme-child-master/
| Style URL: https://pzsz.gov.rs/wp-content/themes/hello-theme-child-master/style.css
| Style Name: Hello Elementor Child
| Style URI: https://github.com/elementor/hello-theme-child/
| Description: Hello Elementor Child is a child theme of Hello Elementor, created by Elementor team...
| Author: Elementor Team
| Author URI: https://elementor.com/
|
| Found By: Urls In Homepage (Passive Detection)
|
| Version: 2.0.0 (80% confidence)
| Found By: Style (Passive Detection)
| - https://pzsz.gov.rs/wp-content/themes/hello-theme-child-master/style.css, Match: 'Version: 2.0.0'
[i] 2 theme(s) Identified.