What this page helps you verify fast
This hub clusters every indexed record for K Elements so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin K Elements (`k-elements`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2025-64362 and CVE-2024-56000, so operators can jump from disclosure to patch validation without scanning the full feed first.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
This hub clusters every indexed record for K Elements so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The K Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible fo...
The K Elements plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.3.9. This is due to the kleo_fb_intialize() function not having sufficient...
Sorted by latest disclosure date so newly published issues surface first.
The K Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...
The K Elements plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.3.9. This is due to the kleo_fb_intialize() function not having sufficient identity verification prior to authenticating a user. This makes it possible for unauthent...