plugin

Element Ready Lite Vulnerabilities

18 known security issues reported for the Element Ready Lite WordPress plugin. Most recent disclosed Apr 16, 2025.

9 medium

Running Element Ready Lite on your site? Check whether your installed version is affected.

Scan your site free

ElementsReady Addons for Elementor <= 6.6.2 - Cross-Site Request Forgery

medium

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.6.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can...

CVSS:
4.3
Affected:
up to 6.6.2
Fixed in:
6.6.3
Disclosed:
Apr 16, 2025

CVE-2025-39546 on NVD →

ElementsReady Addons for Elementor [element-ready-lite] < 6.6.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in quomodosoft ElementsReady Addons for Elementor allows Cross Site Request Forgery. This issue affects ElementsReady Addons for Elementor: from n/a through 6.6.2.

Affected:
up to 6.6.3
Fixed in:
6.6.3
Disclosed:
Apr 16, 2025

CVE-2025-39546 on NVD →

ElementsReady Addons for Elementor [element-ready-lite] < 6.4.9

unknown

[en] The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.8 in inc/Widgets/accordion/output/content.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive priv...

Affected:
up to 6.4.9
Fixed in:
6.4.9
Disclosed:
Dec 17, 2024

CVE-2024-10356 on NVD →

ElementsReady Addons for Elementor <= 6.4.8 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates

medium

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.8 in inc/Widgets/accordion/output/content.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private,...

CVSS:
4.3
Affected:
up to 6.4.8
Fixed in:
6.4.9
Disclosed:
Dec 16, 2024

CVE-2024-10356 on NVD →

ElementsReady Addons for Elementor [element-ready-lite] < 6.4.8

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows DOM-Based XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 6.4.7.

Affected:
up to 6.4.8
Fixed in:
6.4.8
Disclosed:
Dec 9, 2024

CVE-2024-54224 on NVD →

ElementsReady Addons for Elementor <= 6.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...

CVSS:
6.4
Affected:
up to 6.4.7
Fixed in:
6.4.8
Disclosed:
Dec 5, 2024

CVE-2024-54224 on NVD →

ElementsReady Addons for Elementor [element-ready-lite] < 6.4.4

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows Stored XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 6.4.3.

Affected:
up to 6.4.4
Fixed in:
6.4.4
Disclosed:
Nov 9, 2024

CVE-2024-51787 on NVD →

ElementsReady Addons for Elementor <= 6.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...

CVSS:
6.4
Affected:
up to 6.4.3
Fixed in:
6.4.4
Disclosed:
Nov 4, 2024

CVE-2024-51787 on NVD →

ElementsReady Addons for Elementor [element-ready-lite] < 6.4.4

unknown

[en] The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and abov...

Affected:
up to 6.4.4
Fixed in:
6.4.4
Disclosed:
Oct 16, 2024

CVE-2024-9444 on NVD →

ElementsReady Addons for Elementor <= 6.4.3 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

medium

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to...

CVSS:
6.4
Affected:
up to 6.4.3
Fixed in:
6.4.4
Disclosed:
Oct 15, 2024

CVE-2024-9444 on NVD →

ElementsReady Addons for Elementor [element-ready-lite] < 6.4.3

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in QuomodoSoft ElementsReady Addons for Elementor.This issue affects ElementsReady Addons for Elementor: from n/a through 6.4.2.

Affected:
up to 6.4.3
Fixed in:
6.4.3
Disclosed:
Oct 11, 2024

CVE-2024-47353 on NVD →

ElementsReady Addons for Elementor [element-ready-lite] < 6.4.1

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows Stored XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 6.4.0.

Affected:
up to 6.4.1
Fixed in:
6.4.1
Disclosed:
Oct 6, 2024

CVE-2024-47329 on NVD →

ElementsReady Addons for Elementor 6.4.2 - Open Redirect

medium

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Open Redirect in version 6.4.2. This is due to insufficient validation on a redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into p...

CVSS:
6.1
Affected:
6.4.2 – 6.4.2
Fixed in:
6.4.3
Disclosed:
Sep 30, 2024

CVE-2024-47353 on NVD →

ElementsReady Addons for Elementor <= 6.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...

CVSS:
6.4
Affected:
up to 6.4.0
Fixed in:
6.4.1
Disclosed:
Sep 25, 2024

CVE-2024-47329 on NVD →

ElementsReady Addons for Elementor [element-ready-lite] < 6.2.0

unknown

[en] The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 6.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access...

Affected:
up to 6.2.0
Fixed in:
6.2.0
Disclosed:
Jun 6, 2024

CVE-2024-5152 on NVD →

ElementsReady Addons for Elementor <= 6.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 6.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and a...

CVSS:
6.4
Affected:
up to 6.1.0
Fixed in:
6.2.0
Disclosed:
Jun 5, 2024

CVE-2024-5152 on NVD →

ElementsReady Addons for Elementor [element-ready-lite] < 5.9.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows Stored XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 5.8.0.

Affected:
up to 5.9.0
Fixed in:
5.9.0
Disclosed:
May 6, 2024

CVE-2024-34374 on NVD →

ElementsReady Addons for Elementor <= 5.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...

CVSS:
6.4
Affected:
up to 5.8.0
Fixed in:
5.9.0
Disclosed:
May 3, 2024

CVE-2024-34374 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database