_______________________________________________________________ __ _______ _____ \ \ / / __ \ / ____| \ \ /\ / /| |__) | (___ ___ __ _ _ __ ® \ \/ \/ / | ___/ \___ \ / __|/ _` | '_ \ \ /\ / | | ____) | (__| (_| | | | | \/ \/ |_| |_____/ \___|\__,_|_| |_| WordPress Security Scanner Version 4.0.0 An Automattic endeavor https://automattic.com _______________________________________________________________ [i] Updating the Database ... [i] Update completed. [+] URL: https://pzsz.gov.rs/ [109.111.253.121] [+] Started: Sat Jun 6 12:35:21 2026 Interesting Finding(s): [+] Headers | Interesting Entry: Server: Apache | Found By: Headers (Passive Detection) | Confidence: 100% [+] XML-RPC seems to be enabled: https://pzsz.gov.rs/xmlrpc.php | Found By: Link Tag (Passive Detection) | Confidence: 30% | References: | - http://codex.wordpress.org/XML-RPC_Pingback_API | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner/ | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access/ [+] WordPress version 7.0 identified (Latest, released on 2026-05-20). | Found By: Rss Generator (Passive Detection) | - https://pzsz.gov.rs/feed/, https://wordpress.org/?v=7.0 | Confirmed By: Rss Generator (Passive Detection) | - https://pzsz.gov.rs/comments/feed/, https://wordpress.org/?v=7.0 [+] WordPress theme in use: hello-theme-child-master | Location: https://pzsz.gov.rs/wp-content/themes/hello-theme-child-master/ | Style URL: https://pzsz.gov.rs/wp-content/themes/hello-theme-child-master/style.css?ver=2.0.0 | Style Name: Hello Elementor Child | Style URI: https://github.com/elementor/hello-theme-child/ | Description: Hello Elementor Child is a child theme of Hello Elementor, created by Elementor team... | Author: Elementor Team | Author URI: https://elementor.com/ | | Found By: Css Style In Homepage (Passive Detection) | Confirmed By: Css Style In 404 Page (Passive Detection) | | Version: 2.0.0 (80% confidence) | Found By: Style (Passive Detection) | - https://pzsz.gov.rs/wp-content/themes/hello-theme-child-master/style.css?ver=2.0.0, Match: 'Version: 2.0.0' [+] * | Location: https://pzsz.gov.rs/wp-content/plugins/*/ | | Found By: Urls In Homepage (Passive Detection) | | The version could not be determined. [+] 3d-flipbook-dflip-lite | Location: https://pzsz.gov.rs/wp-content/plugins/3d-flipbook-dflip-lite/ | Latest Version: 2.4.30 (up to date) | Last Updated: 2026-06-02 6:21am GMT (4 days ago, per WordPress.org) | Active Installs: 200,000 (per WordPress.org) | | Found By: Urls In Homepage (Passive Detection) | | [!] 1 vulnerability identified: | | [!] Title: DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer <= 2.4.28 - Missing Authorization | UUID: 50fce13a-28c6-411d-a534-9cf7e8893dea | References: | - https://wpscan.com/vulnerability/50fce13a-28c6-411d-a534-9cf7e8893dea | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-49047 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/b3146b41-27d5-465d-a9ec-af4c50a0d612 | | Version: 2.4.30 (20% confidence) | Found By: Query Parameter (Passive Detection) | - https://pzsz.gov.rs/wp-content/plugins/3d-flipbook-dflip-lite/assets/css/dflip.min.css?ver=2.4.30 | - https://pzsz.gov.rs/wp-content/plugins/3d-flipbook-dflip-lite/assets/js/dflip.min.js?ver=2.4.30 [+] document-gallery | Location: https://pzsz.gov.rs/wp-content/plugins/document-gallery/ | Latest Version: 5.1.0 | Last Updated: 2025-12-09 1:05am GMT (5 months ago, per WordPress.org) | Active Installs: 8,000 (per WordPress.org) | | Found By: Urls In Homepage (Passive Detection) | | The version could not be determined. [+] elementor | Location: https://pzsz.gov.rs/wp-content/plugins/elementor/ | Latest Version: 4.1.1 (up to date) | Last Updated: 2026-05-27 11:27am GMT (9 days ago, per WordPress.org) | Active Installs: 10,000,000 (per WordPress.org) | | Found By: Urls In Homepage (Passive Detection) | | Version: 4.1.1 (20% confidence) | Found By: Query Parameter (Passive Detection) | - https://pzsz.gov.rs/wp-content/plugins/elementor/assets/css/frontend.min.css?ver=4.1.1 | - https://pzsz.gov.rs/wp-content/plugins/elementor/assets/js/frontend.min.js?ver=4.1.1 [+] elementor-pro | Location: https://pzsz.gov.rs/wp-content/plugins/elementor-pro/ | | Found By: Urls In Homepage (Passive Detection) | | Version: 3.33.1 (30% confidence) | Found By: Query Parameter (Passive Detection) | - https://pzsz.gov.rs/wp-content/plugins/elementor-pro/assets/lib/sticky/jquery.sticky.min.js?ver=3.33.1 | - https://pzsz.gov.rs/wp-content/plugins/elementor-pro/assets/js/webpack-pro.runtime.min.js?ver=3.33.1 | - https://pzsz.gov.rs/wp-content/plugins/elementor-pro/assets/js/frontend.min.js?ver=3.33.1 [+] embedpress | Location: https://pzsz.gov.rs/wp-content/plugins/embedpress/ | Latest Version: 4.5.4 | Last Updated: 2026-05-25 6:08am GMT (12 days ago, per WordPress.org) | Active Installs: 100,000 (per WordPress.org) | | Found By: Urls In Homepage (Passive Detection) | | [!] 29 vulnerabilities identified: | | [!] Title: EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor < 3.8.0 - Sensitive Data Disclosure | UUID: 082ae437-0f1c-4e63-9e23-4bf0ec732985 | Fixed in: 3.8.0 | References: | - https://wpscan.com/vulnerability/082ae437-0f1c-4e63-9e23-4bf0ec732985 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3371 | | [!] Title: Freemius SDK < 2.5.10 - Reflected Cross-Site Scripting | UUID: 39d1f22f-ea34-4d94-9dc2-12661cf69d36 | Fixed in: 2.0.3 | References: | - https://wpscan.com/vulnerability/39d1f22f-ea34-4d94-9dc2-12661cf69d36 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33999 | | [!] Title: EmbedPress < 3.8.3 - Contributor+ Stored Cross-Site Scripting via Shortcode | UUID: 25d0d190-0748-4518-ad83-ba6a0f9d1319 | Fixed in: 3.8.3 | References: | - https://wpscan.com/vulnerability/25d0d190-0748-4518-ad83-ba6a0f9d1319 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4283 | - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/embedpress/embedpress-382-authenticated-contributor-stored-cross-site-scripting-via-shortcode | | [!] Title: EmbedPress < 3.8.3 - Subscriber+ Plugin Settings Delete | UUID: 8e5b3e67-7640-48a0-b1e0-c118eb9de8d8 | Fixed in: 3.8.3 | References: | - https://wpscan.com/vulnerability/8e5b3e67-7640-48a0-b1e0-c118eb9de8d8 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4282 | - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/embedpress/embedpress-382-missing-authorization-to-authenticated-subscriber-plugin-settings-delete-via-admin-post-remove-and-remove-private-data | | [!] Title: EmbedPress < 3.9.2 - Reflected XSS | UUID: cf323f72-8374-40fe-9e2e-810e46de1ec8 | Fixed in: 3.9.2 | References: | - https://wpscan.com/vulnerability/cf323f72-8374-40fe-9e2e-810e46de1ec8 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5750 | | [!] Title: EmbedPress < 3.9.2 - Reflected XSS | UUID: 3931daac-3899-4169-8625-4c95fd2adafc | Fixed in: 3.9.2 | References: | - https://wpscan.com/vulnerability/3931daac-3899-4169-8625-4c95fd2adafc | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5749 | | [!] Title: EmbedPress < 3.8.4 - Cross-Site Request Forgery | UUID: 7c269cdb-98f4-4207-a6ca-3f4e09c96630 | Fixed in: 3.8.4 | References: | - https://wpscan.com/vulnerability/7c269cdb-98f4-4207-a6ca-3f4e09c96630 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/36ba23ea-7e79-4048-8030-7ed6b2ff45a6 | | [!] Title: EmbedPress < 3.9.6 - Contributor+ Stored XSS | UUID: 643d3453-e3a4-40ee-953f-c8149373ac59 | Fixed in: 3.9.6 | References: | - https://wpscan.com/vulnerability/643d3453-e3a4-40ee-953f-c8149373ac59 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6986 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/ceae0115-268c-401b-876b-3477d10c10e6 | | [!] Title: EmbedPress < 3.9.5 - Missing Authorization | UUID: 3436bbc5-c7b6-4b3b-97fc-786ba66748e1 | Fixed in: 3.9.5 | References: | - https://wpscan.com/vulnerability/3436bbc5-c7b6-4b3b-97fc-786ba66748e1 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/a7cf1c70-9778-4b50-b494-d0b1d0277b35 | | [!] Title: EmbedPress < 3.9.9 - Authenticated(Contributor+) Stored Cross-Site Scripting via Google Calendar Widget Link | UUID: 909d265a-78a8-4222-b244-7b49d2da24e8 | Fixed in: 3.9.9 | References: | - https://wpscan.com/vulnerability/909d265a-78a8-4222-b244-7b49d2da24e8 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1425 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/4d4568c8-f58c-4c37-94b9-6154e5c46928 | | [!] Title: EmbedPress < 3.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | UUID: bebfee16-eb15-41ba-826d-d37f7ced135d | Fixed in: 3.9.9 | References: | - https://wpscan.com/vulnerability/bebfee16-eb15-41ba-826d-d37f7ced135d | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1349 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/631d200f-7b0b-4105-b91e-030af459ba99 | | [!] Title: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 3.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget | UUID: a4a2eae0-473c-4d48-97f8-dbd54b153341 | Fixed in: 3.9.11 | References: | - https://wpscan.com/vulnerability/a4a2eae0-473c-4d48-97f8-dbd54b153341 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2128 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/6189368d-5925-4c84-9f0f-694b9ebcd45e | | [!] Title: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 3.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Wistia Block | UUID: 8896625b-ec99-461f-86c6-c48798287177 | Fixed in: 3.9.11 | References: | - https://wpscan.com/vulnerability/8896625b-ec99-461f-86c6-c48798287177 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1802 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/48511d1a-2fd5-4be4-8409-e99d4aadcdfe | | [!] Title: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 3.9.13 - Authenticated (Contributor+) Stored Cross-site Scripting via 'embedpress_doc_custom_color' | UUID: 1979b942-3a63-4dde-abbb-1b9e01f93720 | Fixed in: 3.9.13 | References: | - https://wpscan.com/vulnerability/1979b942-3a63-4dde-abbb-1b9e01f93720 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2688 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/c5b67927-5993-4e21-af52-8ebe7fee48ab | | [!] Title: EmbedPress < 3.9.13 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Attribute | UUID: 4a2e6bca-2108-465f-ac4d-9376e2834cf8 | Fixed in: 3.9.13 | References: | - https://wpscan.com/vulnerability/4a2e6bca-2108-465f-ac4d-9376e2834cf8 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2468 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/ce3f1310-4d2e-45aa-a3ee-3972a6a31c2e | | [!] Title: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 3.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | UUID: b937c331-3856-4ad2-bebe-cb59fcc06a34 | Fixed in: 3.9.15 | References: | - https://wpscan.com/vulnerability/b937c331-3856-4ad2-bebe-cb59fcc06a34 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3244 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/778d8443-fc0f-4e97-8460-e5ceee8b62a1 | | [!] Title: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 3.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Block | UUID: 136076e8-457e-457b-be41-45e61e7439f7 | Fixed in: 3.9.15 | References: | - https://wpscan.com/vulnerability/136076e8-457e-457b-be41-45e61e7439f7 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3245 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/a427c798-f546-4ca1-98ab-32b433ee5b59 | | [!] Title: EmbedPress < 3.9.12 - Missing Authorization | UUID: 640d7183-9e89-40bc-ab7e-14271ec78475 | Fixed in: 3.9.12 | References: | - https://wpscan.com/vulnerability/640d7183-9e89-40bc-ab7e-14271ec78475 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31274 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/0ce738ee-bbb6-462a-aeae-0523200e320f | | [!] Title: EmbedPress < 3.9.9 - Missing Authorization via handle_calendly_data | UUID: bce8f1ef-f794-4857-a284-0aa864a36946 | Fixed in: 3.9.9 | References: | - https://wpscan.com/vulnerability/bce8f1ef-f794-4857-a284-0aa864a36946 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31284 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/be33065e-dae8-44cf-9f8a-f9971f2743ff | | [!] Title: EmbedPress Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 3.9.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter | UUID: d621d992-84c5-48a6-9a86-a6abf57c332e | Fixed in: 3.9.17 | References: | - https://wpscan.com/vulnerability/d621d992-84c5-48a6-9a86-a6abf57c332e | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4316 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/2af03168-9344-4db0-9b69-2ad1fdb6d472 | | [!] Title: EmbedPress < 3.9.13 - Contributor+ PDF Block Embedding | UUID: ce23ec26-9c61-4546-a179-9fe87019cee4 | Fixed in: 3.9.13 | References: | - https://wpscan.com/vulnerability/ce23ec26-9c61-4546-a179-9fe87019cee4 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1803 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/175e08ce-aec2-427a-90e0-f955711d58b2 | | [!] Title: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor < 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget | UUID: 31dbe99a-cbea-4d47-8e4c-34c26603e87c | Fixed in: 4.0.2 | References: | - https://wpscan.com/vulnerability/31dbe99a-cbea-4d47-8e4c-34c26603e87c | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5571 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/7becdab6-f952-4649-8cea-4efadf841619 | | [!] Title: EmbedPress < 3.9.11 - Authenticated(Contributor+) Stored Cross-Site Scripting via PDF Widget URL | UUID: d5a25afe-f6d4-4ee0-bfbc-1396088aba22 | Fixed in: 3.9.11 | References: | - https://wpscan.com/vulnerability/d5a25afe-f6d4-4ee0-bfbc-1396088aba22 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1565 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/caa97ae8-40a8-4ca1-820b-83675c053bfc | | [!] Title: EmbedPress < 4.0.5 - Missing Authorization | UUID: 3300fd33-de42-4ab3-8674-81594b1f6444 | Fixed in: 4.0.5 | References: | - https://wpscan.com/vulnerability/3300fd33-de42-4ab3-8674-81594b1f6444 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38707 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/f507cec5-d66c-4cb0-8c35-a985aaee1283 | | [!] Title: EmbedPress < 4.0.10 - Unauthenticated Local File Inclusion | UUID: f35019b8-eeec-46af-a65b-829f663401a4 | Fixed in: 4.0.10 | References: | - https://wpscan.com/vulnerability/f35019b8-eeec-46af-a65b-829f663401a4 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-43328 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/21a1b117-945f-49bc-9ea1-313afa93bf32 | | [!] Title: EmbedPress < 4.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting | UUID: faeab079-6002-426c-94f9-f1cc4b761cc9 | Fixed in: 4.0.9 | References: | - https://wpscan.com/vulnerability/faeab079-6002-426c-94f9-f1cc4b761cc9 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-43936 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/31f8bd62-32de-468c-9bed-e03374cb595c | | [!] Title: EmbedPress < 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | UUID: d758bc36-654f-416d-8938-00f091e81501 | Fixed in: 4.1.0 | References: | - https://wpscan.com/vulnerability/d758bc36-654f-416d-8938-00f091e81501 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50461 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/b6851bb9-f15a-4d37-8a15-f4677bd5d62e | | [!] Title: EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor < 4.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'provider_name' | UUID: 91529f39-5792-4fcf-8eac-09437299ea06 | Fixed in: 4.1.4 | References: | - https://wpscan.com/vulnerability/91529f39-5792-4fcf-8eac-09437299ea06 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11203 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/167dedfa-36cc-4b01-8ea4-8eda8742953c | | [!] Title: EmbedPress < 4.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' Attribute | UUID: 189be8b7-70c4-4936-8ab0-2754a9a3dd55 | Fixed in: 4.5.4 | References: | - https://wpscan.com/vulnerability/189be8b7-70c4-4936-8ab0-2754a9a3dd55 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7796 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/a0b5b6bc-5f4f-4cf8-987e-b20e8354d863 | | The version could not be determined. [+] header-footer-elementor | Location: https://pzsz.gov.rs/wp-content/plugins/header-footer-elementor/ | Latest Version: 2.8.8 | Last Updated: 2026-05-27 10:52am GMT (9 days ago, per WordPress.org) | Active Installs: 2,000,000 (per WordPress.org) | | Found By: Urls In Homepage (Passive Detection) | | [!] 12 vulnerabilities identified: | | [!] Title: Elementor - Header, Footer & Blocks Template < 1.5.8 - Contributor+ Stored XSS | UUID: a9412fed-aed3-4931-a504-1a86f876892e | Fixed in: 1.5.8 | References: | - https://wpscan.com/vulnerability/a9412fed-aed3-4931-a504-1a86f876892e | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24256 | - https://www.wordfence.com/blog/2021/04/recent-patches-rock-the-elementor-ecosystem/ | | [!] Title: Elementor Header & Footer Builder < 1.6.25 - Contributor+ Stored Cross-Site Scripting | UUID: 684e290a-1ebe-41eb-8ff7-254162391ecd | Fixed in: 1.6.25 | References: | - https://wpscan.com/vulnerability/684e290a-1ebe-41eb-8ff7-254162391ecd | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1237 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/82644c46-205b-4005-bba8-6b3e45769639 | | [!] Title: Elementor Header & Footer Builder < 1.6.29 - Authenticated (Contributor+) Stored Cross-Site Scripting | UUID: 2a0d3d1f-62f4-44e2-90a4-d3fa41f01650 | Fixed in: 1.6.29 | References: | - https://wpscan.com/vulnerability/2a0d3d1f-62f4-44e2-90a4-d3fa41f01650 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4634 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/f44bb823-bbf3-413b-82b5-a351609270bf | | [!] Title: Elementor Header & Footer Builder < 1.6.27 - Authenticated (Author+) HTML Injection | UUID: a262227b-6c2b-4093-9af1-14fcb7569f24 | Fixed in: 1.6.27 | References: | - https://wpscan.com/vulnerability/a262227b-6c2b-4093-9af1-14fcb7569f24 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2619 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/689eb95b-2f72-4aa4-9f21-6ae186346061 | | [!] Title: Elementor Header & Footer Builder < 1.6.26.1 - Contributor+ Stored XSS | UUID: aa28669a-3c64-4e05-beb7-da41701050a5 | Fixed in: 1.6.26.1 | References: | - https://wpscan.com/vulnerability/aa28669a-3c64-4e05-beb7-da41701050a5 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2618 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/a780ce1b-0758-42ef-88e7-ff8d921eca6e | | [!] Title: Elementor Header & Footer Builder < 1.6.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Title Widget | UUID: a89bb975-5731-4a69-98fe-5888e6ffb4a5 | Fixed in: 1.6.36 | References: | - https://wpscan.com/vulnerability/a89bb975-5731-4a69-98fe-5888e6ffb4a5 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5757 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/b5ab022c-c16c-488b-b004-a7351f8fa3d3 | | [!] Title: Elementor – Header, Footer & Blocks Template < 1.6.36 - Authenticated (Contributor+) Stored Cross-Site Scripting | UUID: c5a24410-a737-49bc-be58-a0403f5e8add | Fixed in: 1.6.36 | References: | - https://wpscan.com/vulnerability/c5a24410-a737-49bc-be58-a0403f5e8add | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-33933 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/8c27fc2c-b515-4314-908d-435a4167ee99 | | [!] Title: Elementor Header & Footer Builder < 1.6.44 - Authenticated (Contributor+) Information Disclosure via Shortcode | UUID: 85f19e03-9939-4f9a-8064-36103ed6dd62 | Fixed in: 1.6.44 | References: | - https://wpscan.com/vulnerability/85f19e03-9939-4f9a-8064-36103ed6dd62 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-10050 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/662f6ae2-2047-4bbf-b4a6-2d536051e389 | | [!] Title: Elementor Header & Footer Builder < 1.6.46 - Author+ Stored XSS via SVG File Upload | UUID: 7241192a-765e-40da-9e91-ca3bafaeba12 | Fixed in: 1.6.46 | References: | - https://wpscan.com/vulnerability/7241192a-765e-40da-9e91-ca3bafaeba12 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-10325 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/7773fd3a-2417-415e-97b0-735e99e62097 | | [!] Title: Elementor Header & Footer Builder < 1.6.47 - Contributor+ Stored XSS via Page Title Widget | UUID: 00d77ab0-981c-4f30-85e1-1db21b070f91 | Fixed in: 1.6.47 | References: | - https://wpscan.com/vulnerability/00d77ab0-981c-4f30-85e1-1db21b070f91 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11230 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/0d82c866-5b35-414e-bd72-30530930d5d8 | | [!] Title: Ultimate Addons for Elementor < 2.4.7 - Subscriber+ Limited Settings Update | UUID: 0c73756d-a808-4678-8918-f402037779d9 | Fixed in: 2.4.7 | References: | - https://wpscan.com/vulnerability/0c73756d-a808-4678-8918-f402037779d9 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8488 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/a4b847b5-9deb-41c4-b976-725249e0098e | | [!] Title: Ultimate Addons for Elementor Lite < 2.5.0 - Author+ Stored XSS | UUID: 4332d49b-d58c-4728-afab-6757ff9e43ee | Fixed in: 2.5.0 | References: | - https://wpscan.com/vulnerability/4332d49b-d58c-4728-afab-6757ff9e43ee | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-9703 | | The version could not be determined. [+] jeg-elementor-kit | Location: https://pzsz.gov.rs/wp-content/plugins/jeg-elementor-kit/ | Latest Version: 3.2.2 | Last Updated: 2026-06-02 9:04am GMT (4 days ago, per WordPress.org) | Active Installs: 300,000 (per WordPress.org) | | Found By: Urls In Homepage (Passive Detection) | | [!] 18 vulnerabilities identified: | | [!] Title: Jeg Elementor Kit < 2.5.7 - Subscriber+ Authorization Bypass | UUID: 9cfd2d4a-d144-4203-b5f6-196e2dcdbca5 | Fixed in: 2.5.7 | References: | - https://wpscan.com/vulnerability/9cfd2d4a-d144-4203-b5f6-196e2dcdbca5 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3794 | | [!] Title: Jeg Elementor Kit < 2.5.7 - Unauthenticated Settings Update | UUID: c431bd21-d2dc-4edc-a5e0-a8e0bdd6d069 | Fixed in: 2.5.7 | References: | - https://wpscan.com/vulnerability/c431bd21-d2dc-4edc-a5e0-a8e0bdd6d069 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3805 | | [!] Title: Jeg Elementor Kit < 2.6.3 - Contributor+ Stored Cross-Site Scripting | UUID: ec997f21-3721-4dd8-ae0e-0645f8bca240 | Fixed in: 2.6.3 | References: | - https://wpscan.com/vulnerability/ec997f21-3721-4dd8-ae0e-0645f8bca240 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1326 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/d108cb36-c072-483e-9746-15b8e7a880c3 | | [!] Title: Jeg Elementor Kit < 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial | UUID: 4e51cecb-0156-4272-9a4a-c37cfe76ffc7 | Fixed in: 2.6.4 | References: | - https://wpscan.com/vulnerability/4e51cecb-0156-4272-9a4a-c37cfe76ffc7 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3162 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/d54c7623-25af-4bf1-a6e0-9022ec26f391 | | [!] Title: Jeg Elementor Kit < 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Box | UUID: a5581897-9384-4de1-8193-f0099e599afd | Fixed in: 2.6.4 | References: | - https://wpscan.com/vulnerability/a5581897-9384-4de1-8193-f0099e599afd | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1327 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/34a42180-9d08-4049-8da8-27ee1f64600a | | [!] Title: Jeg Elementor Kit < 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Banner | UUID: b28a035f-c40a-42f1-a325-ccc5b268ac83 | Fixed in: 2.6.5 | References: | - https://wpscan.com/vulnerability/b28a035f-c40a-42f1-a325-ccc5b268ac83 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3819 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/46868a11-0c82-4bd3-82b5-9a19a5a0cef1 | | [!] Title: Jeg Elementor Kit < 2.6.5 - Contributor+ Stored XSS via Countdown Widget | UUID: 221e015c-ba3f-462a-9155-23da6e6fa7f1 | Fixed in: 2.6.5 | References: | - https://wpscan.com/vulnerability/221e015c-ba3f-462a-9155-23da6e6fa7f1 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3161 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/48a13fb7-bf1a-4bf2-ac3b-3b5a75fec616 | | [!] Title: Jeg Elementor Kit < 2.6.5 - Contributor+ Stored XSS via Elementor Widget URL Custom Attributes | UUID: c8717b6e-2702-4957-b15f-b025c94b4d19 | Fixed in: 2.6.5 | References: | - https://wpscan.com/vulnerability/c8717b6e-2702-4957-b15f-b025c94b4d19 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0334 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/950e9042-1364-4200-8f57-171346075764 | | [!] Title: Jeg Elementor Kit < 2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Tabs and JKit - Accordion Widgets | UUID: 5cafd16a-eb8f-40f7-9944-0c64402bf66f | Fixed in: 2.6.6 | References: | - https://wpscan.com/vulnerability/5cafd16a-eb8f-40f7-9944-0c64402bf66f | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4479 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/c6048ba9-671f-4729-9618-d7a0556a31e6 | | [!] Title: Jeg Elementor Kit < 2.6.8 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File | UUID: a401aef4-3486-4e55-83b8-1dbb01d4f6df | Fixed in: 2.6.8 | References: | - https://wpscan.com/vulnerability/a401aef4-3486-4e55-83b8-1dbb01d4f6df | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6804 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/5491ff65-9060-4b0b-a31d-7b95ea581310 | | [!] Title: Jeg Elementor Kit < 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting | UUID: 28ba86f5-7b53-42e9-9a5d-36cdd7dcfa59 | Fixed in: 2.6.9 | References: | - https://wpscan.com/vulnerability/28ba86f5-7b53-42e9-9a5d-36cdd7dcfa59 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-47390 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/5b624e9b-d21e-43d2-83ad-7760ed63a75c | | [!] Title: Jeg Elementor Kit < 2.6.10 - Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template | UUID: 2f089646-e285-4a09-aecc-5cb8fe100edc | Fixed in: 2.6.10 | References: | - https://wpscan.com/vulnerability/2f089646-e285-4a09-aecc-5cb8fe100edc | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8899 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/4efc9c47-321a-4635-943f-785ffc34d851 | | [!] Title: Jeg Elementor Kit < 2.6.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Countdown Widget | UUID: 1be116a3-1028-4b6c-ad8c-81ec1a1c993d | Fixed in: 2.6.10 | References: | - https://wpscan.com/vulnerability/1be116a3-1028-4b6c-ad8c-81ec1a1c993d | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-10308 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/98aed079-672c-43bb-a5eb-faf8ffc04b71 | | [!] Title: Jeg Elementor Kit < 2.6.12 - Authenticated (Contributor+) Sensitive Information Exposure via Countdown and Off-Canvas | UUID: 2461a3f3-f31c-456a-b491-8db88b25a8f7 | Fixed in: 2.6.12 | References: | - https://wpscan.com/vulnerability/2461a3f3-f31c-456a-b491-8db88b25a8f7 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-13217 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/2136cad8-6b0b-4458-a357-6e98f1ac3e0b | | [!] Title: Jeg Elementor Kit < 2.6.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Button and Countdown Widgets | UUID: 70d12b64-ba42-4def-aa24-8c6d9897d734 | Fixed in: 2.6.13 | References: | - https://wpscan.com/vulnerability/70d12b64-ba42-4def-aa24-8c6d9897d734 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-2944 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/7baa8cca-96a5-4d6b-86d5-53cd1a4675cf | | [!] Title: Jeg Elementor Kit < 2.7.0 - Author+ Stored XSS | UUID: cef78a77-c66d-4d62-8d49-140ca2d04d5b | Fixed in: 2.7.0 | References: | - https://wpscan.com/vulnerability/cef78a77-c66d-4d62-8d49-140ca2d04d5b | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-9978 | | [!] Title: Jeg Elementor Kit < 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget | UUID: ba1b4d9c-ca12-4e2d-ae8b-8c3c27c9e87c | Fixed in: 3.0.2 | References: | - https://wpscan.com/vulnerability/ba1b4d9c-ca12-4e2d-ae8b-8c3c27c9e87c | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-14275 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/8fcb4047-5173-4d10-a4bb-72f1919b9203 | | [!] Title: Jeg Kit for Elementor < 3.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_content_number_prefix' Shortcode Attribute | UUID: dd087275-e61d-45b3-aaa9-647593d31c38 | Fixed in: 3.1.1 | References: | - https://wpscan.com/vulnerability/dd087275-e61d-45b3-aaa9-647593d31c38 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6916 | - https://www.wordfence.com/threat-intel/vulnerabilities/id/5000c86b-b535-48de-b3e0-0dd0d2fd9b1e | | The version could not be determined. [+] quick-event-manager | Location: https://pzsz.gov.rs/wp-content/plugins/quick-event-manager/ | Latest Version: 9.17 | Last Updated: 2025-10-28 6:25pm GMT (7 months ago, per WordPress.org) | Active Installs: 1,000 (per WordPress.org) | | Found By: Urls In Homepage (Passive Detection) | | [!] 6 vulnerabilities identified: | | [!] Title: Unauthorised AJAX Calls via Freemius | UUID: 6dae6dca-7474-4008-9fe5-4c62b9f12d0a | Fixed in: 9.2.17 | Reference: https://wpscan.com/vulnerability/6dae6dca-7474-4008-9fe5-4c62b9f12d0a | | [!] Title: Quick Event Manager < 9.7.5 - Reflected Cross-Site | UUID: 49178a9d-0500-4e3e-8ea1-6cd4eeda2a4e | Fixed in: 9.7.5 | References: | - https://wpscan.com/vulnerability/49178a9d-0500-4e3e-8ea1-6cd4eeda2a4e | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23491 | - https://www.tenable.com/security/research/tra-2023-3 | | [!] Title: Quick Event Manager < 9.7.5 - Registration Deletion/Update via CSRF | UUID: 1f8b493d-04c2-4761-b2e9-728379a8a822 | Fixed in: 9.7.5 | References: | - https://wpscan.com/vulnerability/1f8b493d-04c2-4761-b2e9-728379a8a822 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23974 | | [!] Title: Quick Event Manager < 9.6.5 - Admin+ Stored XSS | UUID: 55c255fb-82be-4af0-8edb-97d067e4cac5 | Fixed in: 9.6.5 | References: | - https://wpscan.com/vulnerability/55c255fb-82be-4af0-8edb-97d067e4cac5 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-46863 | | [!] Title: Quick Event Manager < 9.7.5 - Unauthenticated Stored XSS | UUID: 64c677b2-dc35-4b88-8390-0977e621b90c | Fixed in: 9.7.5 | References: | - https://wpscan.com/vulnerability/64c677b2-dc35-4b88-8390-0977e621b90c | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23979 | | [!] Title: Freemius SDK < 2.5.10 - Reflected Cross-Site Scripting | UUID: 39d1f22f-ea34-4d94-9dc2-12661cf69d36 | Fixed in: 9.8.5.3 | References: | - https://wpscan.com/vulnerability/39d1f22f-ea34-4d94-9dc2-12661cf69d36 | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33999 | | The version could not be determined. [+] wordpress-seo | Location: https://pzsz.gov.rs/wp-content/plugins/wordpress-seo/ | Latest Version: 27.7 (up to date) | Last Updated: 2026-05-27 9:21am GMT (10 days ago, per WordPress.org) | Active Installs: 10,000,000 (per WordPress.org) | | Found By: Comment (Passive Detection) | | Version: 27.7 (60% confidence) | Found By: Comment (Passive Detection) | - https://pzsz.gov.rs/, Match: 'optimized with the Yoast SEO plugin v27.7 -' [i] 10 plugin(s) Identified. [+] hello-elementor | Location: https://pzsz.gov.rs/wp-content/themes/hello-elementor/ | Last Updated: 2026-05-19 10:00pm GMT (17 days ago, per WordPress.org) | Active Installs: 1,000,000 (per WordPress.org) | [!] The version is out of date, the latest version is 3.4.9 | Style URL: https://pzsz.gov.rs/wp-content/themes/hello-elementor/style.css | Style Name: Hello Elementor | Style URI: https://elementor.com/hello-theme/?utm_source=wp-themes&utm_campaign=theme-uri&utm_medium=wp-dash | Description: Hello Elementor is a lightweight and minimalist WordPress theme that was built specifically to work ... | Author: Elementor Team | Author URI: https://elementor.com/?utm_source=wp-themes&utm_campaign=author-uri&utm_medium=wp-dash | | Found By: Urls In Homepage (Passive Detection) | | Version: 3.4.7 (80% confidence) | Found By: Style (Passive Detection) | - https://pzsz.gov.rs/wp-content/themes/hello-elementor/style.css, Match: 'Version: 3.4.7' [+] hello-theme-child-master | Location: https://pzsz.gov.rs/wp-content/themes/hello-theme-child-master/ | Style URL: https://pzsz.gov.rs/wp-content/themes/hello-theme-child-master/style.css | Style Name: Hello Elementor Child | Style URI: https://github.com/elementor/hello-theme-child/ | Description: Hello Elementor Child is a child theme of Hello Elementor, created by Elementor team... | Author: Elementor Team | Author URI: https://elementor.com/ | | Found By: Urls In Homepage (Passive Detection) | | Version: 2.0.0 (80% confidence) | Found By: Style (Passive Detection) | - https://pzsz.gov.rs/wp-content/themes/hello-theme-child-master/style.css, Match: 'Version: 2.0.0' [i] 2 theme(s) Identified.