ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor < 3.10.01 - Authenticated (Admin+) Remote Code Execution
high
The ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 3.10.01 (exclusive). This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
- CVSS:
- 7.2
- Affected:
- up to 3.10.01
- Fixed in:
- 3.10.01
- Disclosed:
- Aug 4, 2026
CVE-2026-13392 on NVD →
ElementsKit Lite <= 3.10.0 - Authenticated (Subsite administrator+) Stored Cross-Site Scripting
medium
The ElementsKit Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subsite administrator-level access and above, to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.01
- Disclosed:
- Jul 14, 2026
CVE-2026-13393 on NVD →
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor <= 3.9.6 - Missing Authorization
medium
The ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.7
- Disclosed:
- May 27, 2026
CVE-2026-49053 on NVD →
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor <= 3.9.6 - Missing Authorization
medium
The ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.6. This makes it possible for authenticated attackers, with contributor-level access and ab...
- CVSS:
- 4.3
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.7
- Disclosed:
- May 27, 2026
CVE-2026-49052 on NVD →
ElementsKit Elementor Addons <= 3.8.2 - Missing Authorization to Unauthenticated Widget Content Overwrite
medium
The ElementsKit Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `Live_Action::reset()` function in all versions up to, and including, 3.8.2 The function is hooked to the WordPress `init` action and triggers when both `post` and `action=el...
- CVSS:
- 6.5
- Affected:
- up to 3.8.2
- Fixed in:
- 3.9.0
- Disclosed:
- May 4, 2026
CVE-2026-4362 on NVD →
ElementsKit Elementor Addons and Templates <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Simple Tab Widget
medium
The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ekit_tab_title' parameter in the Simple Tab widget in all versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p...
- CVSS:
- 6.4
- Affected:
- up to 3.7.9
- Fixed in:
- 3.8.0
- Disclosed:
- Apr 3, 2026
CVE-2026-2600 on NVD →
ElementsKit Elementor addons Lite < 3.7.9 - Missing Authorization
medium
The ElementsKit Elementor addons Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 3.7.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.7.9
- Fixed in:
- 3.7.9
- Disclosed:
- Feb 24, 2026
CVE-2026-23693 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.7.9
unknown
[en] ElementsKit Lite (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API credentials and insufficiently validates certain parameters, including the list paramet...
- Affected:
- up to 3.7.9
- Fixed in:
- 3.7.9
- Disclosed:
- Feb 23, 2026
CVE-2026-23693 on NVD →
ElementsKit Elementor Addons and Templates <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget
medium
The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom widget in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contr...
- CVSS:
- 6.4
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.3
- Disclosed:
- Jul 24, 2025
CVE-2025-3614 on NVD →
ElementsKit Lite <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget
medium
The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin image comparison widget's before/after labels in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...
- CVSS:
- 6.4
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.3
- Disclosed:
- Jun 18, 2025
CVE-2025-4479 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.4.8
unknown
[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...
- Affected:
- up to 3.4.8
- Fixed in:
- 3.4.8
- Disclosed:
- Mar 29, 2025
CVE-2024-11180 on NVD →
ElementsKit Elementor addons <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...
- CVSS:
- 6.4
- Affected:
- up to 3.4.7
- Fixed in:
- 3.4.8
- Disclosed:
- Mar 28, 2025
CVE-2024-11180 on NVD →
ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function
medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such a...
- CVSS:
- 5.3
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.1
- Disclosed:
- Feb 18, 2025
CVE-2025-0968 on NVD →
ElementsKit Elementor addons <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget
medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.1
- Disclosed:
- Feb 14, 2025
CVE-2025-1005 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.2.0
unknown
[en] Missing Authorization vulnerability in Wpmet Elements kit Elementor addons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elements kit Elementor addons: from n/a through 3.1.4.
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- Nov 1, 2024
CVE-2024-37255 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.3.0
unknown
[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.0
- Disclosed:
- Oct 26, 2024
CVE-2024-10091 on NVD →
ElementsKit Elementor addons <= 3.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget
medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 3.2.9
- Fixed in:
- 3.3.0
- Disclosed:
- Oct 25, 2024
CVE-2024-10091 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.2.8
unknown
[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wi...
- Affected:
- up to 3.2.8
- Fixed in:
- 3.2.8
- Disclosed:
- Sep 25, 2024
CVE-2024-8546 on NVD →
ElementsKit Elementor addons <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget
medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with co...
- CVSS:
- 6.4
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.8
- Disclosed:
- Sep 24, 2024
CVE-2024-8546 on NVD →
ElementsKit Elementor addons <= 3.2.0 - Unauthenticated Information Exposure via ekit_widgetarea_content Function
medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages...
- CVSS:
- 5.3
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.1
- Disclosed:
- Jul 18, 2024
CVE-2024-6455 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.2.1
unknown
[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts,...
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.1
- Disclosed:
- Jul 18, 2024
CVE-2024-6455 on NVD →
Elements kit Elementor addons <= 3.1.4 - Missing Authorization
medium
The Elements kit Elementor addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor() function in versions up to, and including, 3.1.4. This makes it possible for unauthenticated attackers to update post data.
- CVSS:
- 5.3
- Affected:
- up to 3.1.4
- Fixed in:
- 3.2.0
- Disclosed:
- Jun 27, 2024
CVE-2024-37255 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 2.9.2
unknown
[en] Missing Authorization vulnerability in Wpmet Elements kit Elementor addons.This issue affects Elements kit Elementor addons: from n/a through 2.9.0.
- Affected:
- up to 2.9.2
- Fixed in:
- 2.9.2
- Disclosed:
- Jun 19, 2024
CVE-2023-39993 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.1.1
unknown
[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the generate_navigation_markup function of the Onepage Scroll module. This makes it possible for authenticated attackers, with contributor-level access and above, to include a...
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- May 2, 2024
CVE-2024-3499 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.1.3
unknown
[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions 3.0.7 through 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abo...
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- May 2, 2024
CVE-2024-3650 on NVD →
ElementsKit Elementor addons 3.0.7 - 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget
medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions 3.0.7 through 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, t...
- CVSS:
- 6.4
- Affected:
- 3.0.7 – 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- Apr 30, 2024
CVE-2024-3650 on NVD →
ElementsKit Elementor addons <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Module
high
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the generate_navigation_markup function of the Onepage Scroll module. This makes it possible for authenticated attackers, with contributor-level access and above, to include and ex...
- CVSS:
- 8.8
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.1
- Disclosed:
- Apr 22, 2024
CVE-2024-3499 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.0.7
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Elements kit Elementor addons allows Stored XSS.This issue affects Elements kit Elementor addons: from n/a through 3.0.6.
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.7
- Disclosed:
- Apr 17, 2024
CVE-2024-32505 on NVD →
ElementsKit Elementor addons Lite <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementsKit Elementor addons Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...
- CVSS:
- 6.4
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.7
- Disclosed:
- Apr 15, 2024
CVE-2024-32505 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.1.0
unknown
[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with co...
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
- Disclosed:
- Apr 4, 2024
CVE-2024-2803 on NVD →
ElementsKit Elementor addons <= 3.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contrib...
- CVSS:
- 6.4
- Affected:
- up to 3.0.7
- Fixed in:
- 3.1.0
- Disclosed:
- Apr 3, 2024
CVE-2024-2803 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.0.7
unknown
[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button ID parameter in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above...
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.7
- Disclosed:
- Mar 30, 2024
CVE-2024-1238 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.0.7
unknown
[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the render_raw function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, all...
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.7
- Disclosed:
- Mar 30, 2024
CVE-2024-2047 on NVD →
ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Local File Inclusion in render_raw
high
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the render_raw function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing...
- CVSS:
- 8.8
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.7
- Disclosed:
- Mar 29, 2024
CVE-2024-2047 on NVD →
ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button ID parameter in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to...
- CVSS:
- 6.4
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.7
- Disclosed:
- Mar 29, 2024
CVE-2024-1238 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.0.5
unknown
[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blog post read more button in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access a...
- Affected:
- up to 3.0.5
- Fixed in:
- 3.0.5
- Disclosed:
- Mar 16, 2024
CVE-2024-1239 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.0.4
unknown
[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar element attributes in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level ac...
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.4
- Disclosed:
- Mar 16, 2024
CVE-2023-6525 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.0.6
unknown
[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access...
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.6
- Disclosed:
- Mar 16, 2024
CVE-2024-2042 on NVD →
ElementsKit Elementor addons <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blog post read more button in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and ab...
- CVSS:
- 6.4
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.5
- Disclosed:
- Mar 15, 2024
CVE-2024-1239 on NVD →
ElementsKit Elementor addons <= 3.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget
medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...
- CVSS:
- 6.4
- Affected:
- up to 3.0.5
- Fixed in:
- 3.0.6
- Disclosed:
- Mar 15, 2024
CVE-2024-2042 on NVD →
ElementsKit Elementor addons <= 3.0.3 - Authenticated(Editor+) Stored Cross-Site Scripting
medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar element attributes in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access,...
- CVSS:
- 5.5
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.4
- Disclosed:
- Mar 15, 2024
CVE-2023-6525 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.0.4
unknown
[en] The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to obtain contents of posts in draft, private or pending review status tha...
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.4
- Disclosed:
- Jan 11, 2024
CVE-2023-6582 on NVD →
ElementsKit Lite <= 3.0.3 - Unauthenticated Sensitive Information Exposure
medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to obtain contents of posts in draft, private or pending review status that sho...
- CVSS:
- 5.3
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.4
- Disclosed:
- Jan 8, 2024
CVE-2023-6582 on NVD →
Elements kit Elementor addons <= 2.9.1 - Missing Authorization
medium
The Elements kit Elementor addons plugin for WordPress is vulnerable to unauthorized admin notice dismissal due to a missing capability check on the dismiss_ajax_call function in versions up to, and including, 2.9.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss...
- CVSS:
- 5.4
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.2
- Disclosed:
- Aug 23, 2023
CVE-2023-39993 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 2.2.0
unknown
[en] The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- May 5, 2021
CVE-2021-24258 on NVD →
Elements Kit Lite/Pro <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
- CVSS:
- 5.4
- Affected:
- up to 2.1.7
- Fixed in:
- 2.2.0
- Disclosed:
- Apr 13, 2021
CVE-2021-24258 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 2.2.0
unknown
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress Elements kit Elementor addons plugin (versions <= 2.1.7).
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- Apr 13, 2021
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.5.3
unknown
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
CVE-2025-3614 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.5.3
unknown
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
CVE-2025-4479 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.4.1
unknown
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
CVE-2025-0968 on NVD →
ElementsKit Elementor Addons and Templates [elementskit-lite] < 3.4.1
unknown
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.1
CVE-2025-1005 on NVD →