ElementInvader Addons for Elementor <= 1.4.3 - Unauthenticated Stored Cross-Site Scripting
high
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wh...
- CVSS:
- 7.2
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Jul 7, 2026
CVE-2026-57376 on NVD →
ElementInvader Addons for Elementor <= 1.4.2 - Authenticated (Subscriber+) SQL Injection
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscribe...
- CVSS:
- 6.5
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- Mar 23, 2026
CVE-2026-25007 on NVD →
ElementInvader Addons for Elementor <= 1.4.1 - Missing Authorization
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.2
- Disclosed:
- Feb 5, 2026
CVE-2026-25028 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] <= 1.4.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.1.
- Affected:
- up to 1.4.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2026
CVE-2026-25028 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] < 1.4.1
unknown
[en] The ElementInvader Addons for Elementor WordPress plugin before 1.4.1 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses due to missing authorization on the elementinvader_addons_for_elementor_forms_send_form action.
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
- Disclosed:
- Nov 5, 2025
CVE-2025-10873 on NVD →
Elementinvader Addons for Elementor <= 1.4.0 - Unauthenticated Arbitrary Email Sending
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Unauthenticated Arbitrary Email Sending in all versions up to, and including, 1.4.0. This is due to the 'elementinvader_addons_for_elementor_forms_send_form' AJAX endpoint allowing user supplied content for the email along with the to and fro...
- CVSS:
- 5.8
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.1
- Disclosed:
- Oct 15, 2025
CVE-2025-10873 on NVD →
ElementInvader Addons for Elementor <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.7
- Disclosed:
- Aug 27, 2025
CVE-2025-58205 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] < 1.3.7
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor allows DOM-Based XSS. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.6.
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7
- Disclosed:
- Aug 27, 2025
CVE-2025-58205 on NVD →
ElementInvader Addons for Elementor <= 1.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.6
- Disclosed:
- May 19, 2025
CVE-2025-48288 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] < 1.3.6
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor allows Stored XSS. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.5.
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- May 19, 2025
CVE-2025-48288 on NVD →
ElementInvader Addons for Elementor <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.4
- Disclosed:
- Jan 24, 2025
CVE-2025-24729 on NVD →
ElementInvader Addons for Elementor <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.1
- Disclosed:
- Jan 24, 2025
CVE-2025-24578 on NVD →
ElementInvader Addons for Elementor <= 1.3.1 - Missing Authorization
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.2
- Disclosed:
- Jan 24, 2025
CVE-2025-24618 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] < 1.3.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElementInvader ElementInvader Addons for Elementor allows Stored XSS. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.3.
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- Jan 24, 2025
CVE-2025-24729 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] < 1.3.2
unknown
[en] Missing Authorization vulnerability in ElementInvader ElementInvader Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.1.
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Jan 24, 2025
CVE-2025-24618 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] < 1.3.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElementInvader ElementInvader Addons for Elementor allows DOM-Based XSS. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.0.
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- Jan 24, 2025
CVE-2025-24578 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] < 1.2.7
unknown
[en] Path Traversal vulnerability in ElementInvader ElementInvader Addons for Elementor allows PHP Local File Inclusion.This issue affects ElementInvader Addons for Elementor: from n/a through 1.2.6.
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Jan 15, 2025
CVE-2025-22786 on NVD →
ElementInvader Addons for Elementor <= 1.2.6 - Authenticated (Contributor+) Local File Inclusion
high
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.6. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP...
- CVSS:
- 8.8
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.7
- Disclosed:
- Jan 13, 2025
CVE-2025-22786 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] < 1.3.2
unknown
[en] The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.1 via the eli_option_value shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract arbitrary options from...
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Dec 12, 2024
CVE-2024-12059 on NVD →
ElementInvader Addons for Elementor <= 1.3.1 - Missing Authorization to Arbitrary Options Read
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.1 via the eli_option_value shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract arbitrary options from the...
- CVSS:
- 4.3
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.2
- Disclosed:
- Dec 11, 2024
CVE-2024-12059 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] < 1.3.0
unknown
[en] The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.9 via the Page Loader widget. This makes it possible for authenticated attackers, with contributor-level access and above, to view private/draft/password protected...
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- Oct 19, 2024
CVE-2024-9889 on NVD →
ElementInvader Addons for Elementor <= 1.2.9 - Authenticated (Contributor+) Information Exposure
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.9 via the Page Loader widget. This makes it possible for authenticated attackers, with contributor-level access and above, to view private/draft/password protected posts...
- CVSS:
- 4.3
- Affected:
- up to 1.2.9
- Fixed in:
- 1.3.0
- Disclosed:
- Oct 18, 2024
CVE-2024-9889 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] < 1.2.9
unknown
[en] The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget redirect URL in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...
- Affected:
- up to 1.2.9
- Fixed in:
- 1.2.9
- Disclosed:
- Oct 16, 2024
CVE-2024-9888 on NVD →
ElementInvader Addons for Elementor <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget redirect URL in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe...
- CVSS:
- 5.4
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.9
- Disclosed:
- Oct 15, 2024
CVE-2024-9888 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] < 1.2.8
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ElementInvader ElementInvader Addons for Elementor allows Stored XSS.This issue affects ElementInvader Addons for Elementor: from n/a through 1.2.7.
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.8
- Disclosed:
- Oct 5, 2024
CVE-2024-47630 on NVD →
ElementInvader Addons for Elementor <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.8
- Disclosed:
- Sep 30, 2024
CVE-2024-47630 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] < 1.2.5
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ElementInvader ElementInvader Addons for Elementor allows Stored XSS.This issue affects ElementInvader Addons for Elementor: from n/a through 1.2.4.
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Jul 20, 2024
CVE-2024-38705 on NVD →
ElementInvader Addons for Elementor <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.5
- Disclosed:
- Jul 11, 2024
CVE-2024-38705 on NVD →
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor] < 1.2.3
unknown
[en] The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link in the EliSlider in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor...
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Mar 16, 2024
CVE-2024-2308 on NVD →
ElementInvader Addons for Elementor <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link in the EliSlider in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor acce...
- CVSS:
- 6.4
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.3
- Disclosed:
- Mar 15, 2024
CVE-2024-2308 on NVD →