Essential Addons for Elementor <= 6.7.1 - Unauthenticated Privilege Escalation
high
The Essential Addons for Elementor plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.1. This is due to missing validation against reserved wp_insert_user() data keys (such as 'role') when building the custom profile fields array, allowing user-controlled field labels to ov...
- CVSS:
- 7.3
- Affected:
- up to 6.7.1
- Fixed in:
- 6.7.2
- Disclosed:
- Aug 12, 2026
CVE-2026-18039 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets < 6.6.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6.6.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, t...
- CVSS:
- 6.4
- Affected:
- up to 6.6.10
- Fixed in:
- 6.6.10
- Disclosed:
- Jul 30, 2026
CVE-2026-13344 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets < 6.6.10 - Missing Authorization
medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 6.6.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 6.6.10
- Fixed in:
- 6.6.10
- Disclosed:
- Jul 30, 2026
CVE-2026-13345 on NVD →
Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget
medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 6.6.11
- Fixed in:
- 6.7.0
- Disclosed:
- Jul 20, 2026
CVE-2026-15145 on NVD →
Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings
medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 6.6.11
- Fixed in:
- 6.7.0
- Disclosed:
- Jul 20, 2026
CVE-2026-15156 on NVD →
Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection
high
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10. This is due to insufficient server-side validation of a Login/Register widget setting used to construct...
- CVSS:
- 8.8
- Affected:
- up to 6.6.10
- Fixed in:
- 6.6.11
- Disclosed:
- Jul 10, 2026
CVE-2026-15155 on NVD →
Essential Addons for Elementor <= 6.6.2 - Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup
medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on event titles sourced from The Events Calend...
- CVSS:
- 6.4
- Affected:
- up to 6.6.2
- Fixed in:
- 6.6.3
- Disclosed:
- Jul 7, 2026
CVE-2026-6459 on NVD →
Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler
medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated at...
- CVSS:
- 5.3
- Affected:
- up to 6.6.4
- Fixed in:
- 6.6.5
- Disclosed:
- Jun 5, 2026
CVE-2026-7665 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_user
medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role validation in the 'register_user' function, which only blocks the 'administrator' role. This makes it possi...
- CVSS:
- 6.5
- Affected:
- up to 6.5.13
- Fixed in:
- 6.6.0
- Disclosed:
- May 13, 2026
CVE-2026-5193 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets < 6.6.0 - Missing Authorization
medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 6.6.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 6.6.0
- Fixed in:
- 6.6.0
- Disclosed:
- Apr 22, 2026
CVE-2026-25440 on NVD →
Essential Addons for Elementor <= 6.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget
medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Info Box widget in all versions up to, and including, 6.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...
- CVSS:
- 6.4
- Affected:
- up to 6.5.9
- Fixed in:
- 6.5.10
- Disclosed:
- Feb 13, 2026
CVE-2026-1512 on NVD →
Essential Addons for Elementor <= 6.5.5 - Missing Authorization to Unauthenticated Sensitive Information Exposure
medium
The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information for products with draft, pen...
- CVSS:
- 5.3
- Affected:
- up to 6.5.5
- Fixed in:
- 6.5.6
- Disclosed:
- Jan 15, 2026
CVE-2026-1004 on NVD →
Essential Addons for Elementor <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web sc...
- CVSS:
- 6.4
- Affected:
- up to 6.5.3
- Fixed in:
- 6.5.4
- Disclosed:
- Jan 6, 2026
CVE-2025-69092 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] <= 6.5.3 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows DOM-Based XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.5.3.
- Affected:
- up to 6.5.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 30, 2025
CVE-2025-69092 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.5.4
unknown
[en] The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in all versions up to, and including, 6.5.3. This is due to insufficient input sanitization and output escaping in the Event Calendar widget's cus...
- Affected:
- up to 6.5.4
- Fixed in:
- 6.5.4
- Disclosed:
- Dec 17, 2025
CVE-2025-13977 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in all versions up to, and including, 6.5.3. This is due to insufficient input sanitization and output escaping in the Event Calendar widget's custom a...
- CVSS:
- 6.4
- Affected:
- up to 6.5.3
- Fixed in:
- 6.5.4
- Disclosed:
- Dec 16, 2025
CVE-2025-13977 on NVD →
Essential Addons for Elementor <= 6.5.5 - Missing Authorization
medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.5.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 6.5.5
- Fixed in:
- 6.5.6
- Disclosed:
- Nov 18, 2025
CVE-2026-23543 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] <= 6.2.4 (unfixed)
unknown
[en] Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a through <= 6.2.4.
- Affected:
- up to 6.2.4
- Fix:
- No patched version reported
- Disclosed:
- Oct 31, 2025
CVE-2025-64352 on NVD →
Essential Addons for Elementor <= 6.2.4 - Missing Authorization
medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.2.4. This makes it possible for authenticated attackers, with Author-level access and above, to per...
- CVSS:
- 4.3
- Affected:
- up to 6.2.4
- Fixed in:
- 6.3.0
- Disclosed:
- Sep 17, 2025
CVE-2025-64352 on NVD →
Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items'
medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘data-gallery-items’ parameter in all versions up to, and including, 6.2.2 due to insufficient input sanitization and output escaping. This makes it possible for...
- CVSS:
- 6.4
- Affected:
- up to 6.2.2
- Fixed in:
- 6.2.3
- Disclosed:
- Aug 14, 2025
CVE-2025-8451 on NVD →
Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets
medium
The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and output escaping. This ma...
- CVSS:
- 6.4
- Affected:
- up to 6.1.19
- Fixed in:
- 6.1.20
- Disclosed:
- Jul 7, 2025
CVE-2025-6244 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 6.0.4
- Fixed in:
- 6.0.5
- Disclosed:
- Jul 2, 2025
CVE-2024-5647 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget
medium
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_event_details_text parameter of Event Calendar Widget in all versions up to, and including, 6.1.12 due to insufficient input sanitizat...
- CVSS:
- 6.4
- Affected:
- up to 6.1.12
- Fixed in:
- 6.1.13
- Disclosed:
- Jun 6, 2025
CVE-2024-9993 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget
medium
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_pricing_item_tooltip_content parameter of the Pricing Table Widget in all versions up to, and including, 6.1.12 due to insufficient in...
- CVSS:
- 6.4
- Affected:
- up to 6.1.12
- Fixed in:
- 6.1.13
- Disclosed:
- Jun 6, 2025
CVE-2024-9994 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.15
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Reflected XSS. This issue affects Essential Addons for Elementor: from n/a through 6.0.14.
- Affected:
- up to 6.0.15
- Fixed in:
- 6.0.15
- Disclosed:
- Apr 17, 2025
CVE-2025-24752 on NVD →
Essential Addons for Elementor <= 6.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web sc...
- CVSS:
- 6.4
- Affected:
- up to 6.1.9
- Fixed in:
- 6.1.10
- Disclosed:
- Apr 16, 2025
CVE-2025-39590 on NVD →
Essential Addons for Elementor <= 6.1.9 - Authenticated (Contributor+) Information Disclosure
medium
The Essential Addons for Elementor – Popular Elementor Addon With Ready Templates, Advanced Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.1.9. This makes it possible for authenticated attackers, with Contributor-level ac...
- CVSS:
- 4.3
- Affected:
- up to 6.1.9
- Fixed in:
- 6.1.10
- Disclosed:
- Apr 16, 2025
CVE-2025-39589 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.10
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper Essential Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Essential Addons for Elementor: from n/a through 6.1.9.
- Affected:
- up to 6.1.10
- Fixed in:
- 6.1.10
- Disclosed:
- Apr 16, 2025
CVE-2025-39589 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.10
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS. This issue affects Essential Addons for Elementor: from n/a through 6.1.9.
- Affected:
- up to 6.1.10
- Fixed in:
- 6.1.10
- Disclosed:
- Apr 16, 2025
CVE-2025-39590 on NVD →
Essential Addons for Elementor <= 6.0.14 - Reflected Cross-Site Scripting
medium
The Essential Addons for Elementor – Popular Elementor Addon With Ready Templates, Advanced Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 6.0.14 due to insufficient input sanitization and output escaping. This makes it pos...
- CVSS:
- 6.1
- Affected:
- up to 6.0.14
- Fixed in:
- 6.0.15
- Disclosed:
- Feb 4, 2025
CVE-2025-24752 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.8
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 6.0.7.
- Affected:
- up to 6.0.8
- Fixed in:
- 6.0.8
- Disclosed:
- Dec 31, 2024
CVE-2024-56063 on NVD →
Essential Addons for Elementor <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web sc...
- CVSS:
- 6.4
- Affected:
- up to 6.0.7
- Fixed in:
- 6.0.8
- Disclosed:
- Dec 18, 2024
CVE-2024-56063 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.10
unknown
[en] The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_lostpassword_user_email_controls' function. This makes it possible for au...
- Affected:
- up to 6.0.10
- Fixed in:
- 6.0.10
- Disclosed:
- Nov 15, 2024
CVE-2024-8979 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.8
unknown
[en] The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nomore_items_text’ parameter in all versions up to, and including, 6.0.7 due to insufficient input sanitization and output escaping....
- Affected:
- up to 6.0.8
- Fixed in:
- 6.0.8
- Disclosed:
- Nov 15, 2024
CVE-2024-8961 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.10
unknown
[en] The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_register_user_email_controls' function. This makes it possible for authen...
- Affected:
- up to 6.0.10
- Fixed in:
- 6.0.10
- Disclosed:
- Nov 15, 2024
CVE-2024-8978 on NVD →
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nomore_items_text’ parameter in all versions up to, and including, 6.0.7 due to insufficient input sanitization and output escaping. This...
- CVSS:
- 6.4
- Affected:
- up to 6.0.7
- Fixed in:
- 6.0.8
- Disclosed:
- Nov 14, 2024
CVE-2024-8961 on NVD →
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation
high
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_lostpassword_user_email_controls' function. This makes it possible for authent...
- CVSS:
- 8
- Affected:
- up to 6.0.9
- Fixed in:
- 6.0.10
- Disclosed:
- Nov 14, 2024
CVE-2024-8979 on NVD →
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Contributor+) Sensitive Information Exposure
medium
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_register_user_email_controls' function. This makes it possible for authenticat...
- CVSS:
- 5.7
- Affected:
- up to 6.0.9
- Fixed in:
- 6.0.10
- Disclosed:
- Nov 14, 2024
CVE-2024-8978 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 4.6.5
unknown
[en] The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the...
- Affected:
- up to 4.6.5
- Fixed in:
- 4.6.5
- Disclosed:
- Oct 16, 2024
CVE-2021-4447 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 4.6.5
unknown
[en] The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized...
- Affected:
- up to 4.6.5
- Fixed in:
- 4.6.5
- Disclosed:
- Oct 16, 2024
CVE-2021-4446 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.4
unknown
[en] The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escap...
- Affected:
- up to 6.0.4
- Fixed in:
- 6.0.4
- Disclosed:
- Sep 13, 2024
CVE-2024-8742 on NVD →
Essential Addons for Elementor <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery Widget
medium
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping o...
- CVSS:
- 6.4
- Affected:
- up to 6.0.3
- Fixed in:
- 6.0.4
- Disclosed:
- Sep 12, 2024
CVE-2024-8742 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.4
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping on user sup...
- Affected:
- up to 6.0.4
- Fixed in:
- 6.0.4
- Disclosed:
- Sep 11, 2024
CVE-2024-8440 on NVD →
Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping on user supplied...
- CVSS:
- 6.4
- Affected:
- up to 6.0.3
- Fixed in:
- 6.0.4
- Disclosed:
- Sep 10, 2024
CVE-2024-8440 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.0
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘no_more_items_text’ parameter in all versions up to, and including, 5.9.27 due to insufficient input sanitization and output escaping. This...
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.0
- Disclosed:
- Aug 13, 2024
CVE-2024-7092 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via no_more_items_text Parameter
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘no_more_items_text’ parameter in all versions up to, and including, 5.9.27 due to insufficient input sanitization and output escaping. This makes...
- CVSS:
- 6.4
- Affected:
- up to 5.9.27
- Fixed in:
- 6.0.0
- Disclosed:
- Aug 12, 2024
CVE-2024-7092 on NVD →
Essential Addons for Elementor <= 5.9.26 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...
- CVSS:
- 6.4
- Affected:
- up to 5.9.26
- Fixed in:
- 5.9.27
- Disclosed:
- Aug 1, 2024
CVE-2024-39649 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.27
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 5.9.26.
- Affected:
- up to 5.9.27
- Fixed in:
- 5.9.27
- Disclosed:
- Aug 1, 2024
CVE-2024-39649 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.24
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_js’ parameter in all versions up to, and including, 5.9.23 due to insufficient input sanitization and output escaping. This makes it...
- Affected:
- up to 5.9.24
- Fixed in:
- 5.9.24
- Disclosed:
- Jun 11, 2024
CVE-2024-5189 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.23 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_js’ parameter in all versions up to, and including, 5.9.23 due to insufficient input sanitization and output escaping. This makes it possi...
- CVSS:
- 6.4
- Affected:
- up to 5.9.23
- Fixed in:
- 5.9.24
- Disclosed:
- Jun 10, 2024
CVE-2024-5189 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.23
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_manual_calendar_events' function in all versions up to, and including, 5.9.22 due to insufficient input sanitization and output escaping...
- Affected:
- up to 5.9.23
- Fixed in:
- 5.9.23
- Disclosed:
- Jun 6, 2024
CVE-2024-5188 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.22 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_manual_calendar_events' function in all versions up to, and including, 5.9.22 due to insufficient input sanitization and output escaping. Thi...
- CVSS:
- 6.4
- Affected:
- up to 5.9.22
- Fixed in:
- 5.9.23
- Disclosed:
- Jun 5, 2024
CVE-2024-5188 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 5.9.15.
- Affected:
- up to 5.9.16
- Fixed in:
- 5.9.16
- Disclosed:
- Jun 3, 2024
CVE-2024-34764 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.22
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Feed component in all versions up to, and including, 5.9.21 due to insufficient input sanitization and output escaping. This makes it...
- Affected:
- up to 5.9.22
- Fixed in:
- 5.9.22
- Disclosed:
- May 30, 2024
CVE-2024-5073 on NVD →
Essential Addons for Elementor <= 5.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Feed
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Feed component in all versions up to, and including, 5.9.21 due to insufficient input sanitization and output escaping. This makes it poss...
- CVSS:
- 6.4
- Affected:
- up to 5.9.21
- Fixed in:
- 5.9.22
- Disclosed:
- May 29, 2024
CVE-2024-5073 on NVD →
Essential Addons for Elementor <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...
- CVSS:
- 6.4
- Affected:
- up to 5.9.15
- Fixed in:
- 5.9.16
- Disclosed:
- May 17, 2024
CVE-2024-34764 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.8.9
unknown
[en] Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n/a through 5.8.8.
- Affected:
- up to 5.8.9
- Fixed in:
- 5.8.9
- Disclosed:
- May 17, 2024
CVE-2023-41955 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.21
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_ext_toc_title_tag’ parameter in versions up to, and including, 5.9.20 due to insufficient input sanitization and output escaping. This...
- Affected:
- up to 5.9.21
- Fixed in:
- 5.9.21
- Disclosed:
- May 14, 2024
CVE-2024-4624 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.20 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_ext_toc_title_tag’ parameter in versions up to, and including, 5.9.20 due to insufficient input sanitization and output escaping. This make...
- CVSS:
- 6.4
- Affected:
- up to 5.9.20
- Fixed in:
- 5.9.21
- Disclosed:
- May 13, 2024
CVE-2024-4624 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.20
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table' widgets in all versions up to, and including, 5.9.19 due to insuffici...
- Affected:
- up to 5.9.20
- Fixed in:
- 5.9.20
- Disclosed:
- May 10, 2024
CVE-2024-4448 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.20
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Interactive Circle widget in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on...
- Affected:
- up to 5.9.20
- Fixed in:
- 5.9.20
- Disclosed:
- May 10, 2024
CVE-2024-4275 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.20
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Fancy Text', 'Filter Gallery', 'Sticky Video', 'Content Ticker', 'Woo Product Gallery', & 'Twitter Feed' widgets in all versions up...
- Affected:
- up to 5.9.20
- Fixed in:
- 5.9.20
- Disclosed:
- May 10, 2024
CVE-2024-4449 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table'
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table' widgets in all versions up to, and including, 5.9.19 due to insufficient i...
- CVSS:
- 6.4
- Affected:
- up to 5.9.19
- Fixed in:
- 5.9.20
- Disclosed:
- May 9, 2024
CVE-2024-4448 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Interactive Circles'
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Interactive Circle widget in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user...
- CVSS:
- 6.4
- Affected:
- up to 5.9.19
- Fixed in:
- 5.9.20
- Disclosed:
- May 9, 2024
CVE-2024-4275 on NVD →
Essential Addons for Elementor <= 5.9.19 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Several Widgets
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Fancy Text', 'Filter Gallery', 'Sticky Video', 'Content Ticker', 'Woo Product Gallery', & 'Twitter Feed' widgets in all versions up to,...
- CVSS:
- 6.4
- Affected:
- up to 5.9.19
- Fixed in:
- 5.9.20
- Disclosed:
- May 9, 2024
CVE-2024-4449 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery & Interactive Circle widgets in all versions up to, and including, 5.9.15 due to insufficient input sanitization...
- Affected:
- up to 5.9.16
- Fixed in:
- 5.9.16
- Disclosed:
- May 2, 2024
CVE-2024-3728 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_team_members_image_rounded parameter in the Team Members widget in all versions up to, and including, 5.9.15 due to insufficient input s...
- Affected:
- up to 5.9.16
- Fixed in:
- 5.9.16
- Disclosed:
- May 2, 2024
CVE-2024-4003 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.18
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_event_text_color’ parameter in versions up to, and including, 5.9.17 due to insufficient input sanitization and output escaping. This m...
- Affected:
- up to 5.9.18
- Fixed in:
- 5.9.18
- Disclosed:
- May 2, 2024
CVE-2024-4156 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_event_text_color’ parameter in versions up to, and including, 5.9.17 due to insufficient input sanitization and output escaping. This makes...
- CVSS:
- 6.4
- Affected:
- up to 5.9.17
- Fixed in:
- 5.9.18
- Disclosed:
- Apr 30, 2024
CVE-2024-4156 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery() functi...
- Affected:
- up to 5.9.16
- Fixed in:
- 5.9.16
- Disclosed:
- Apr 25, 2024
CVE-2024-3733 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_team_members_image_rounded parameter in the Team Members widget in all versions up to, and including, 5.9.15 due to insufficient input saniti...
- CVSS:
- 6.4
- Affected:
- up to 5.9.15
- Fixed in:
- 5.9.16
- Disclosed:
- Apr 24, 2024
CVE-2024-4003 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery & Interactive Circle widgets in all versions up to, and including, 5.9.15 due to insufficient input sanitization and o...
- CVSS:
- 6.4
- Affected:
- up to 5.9.15
- Fixed in:
- 5.9.16
- Disclosed:
- Apr 24, 2024
CVE-2024-3728 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Information Exposure
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery() functions....
- CVSS:
- 5.3
- Affected:
- up to 5.9.15
- Fixed in:
- 5.9.16
- Disclosed:
- Apr 24, 2024
CVE-2024-3733 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.15
unknown
[en] The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attributes of widgets in all versions up to, and including, 5.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...
- Affected:
- up to 5.9.15
- Fixed in:
- 5.9.15
- Disclosed:
- Apr 17, 2024
CVE-2024-3333 on NVD →
Essential Addons for Elementor <= 5.9.14 - Authenticated (Contributor+) Store Cross-Site Scripting via Widget URL Attribute
medium
The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attributes of widgets in all versions up to, and including, 5.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 5.9.14
- Fixed in:
- 5.9.15
- Disclosed:
- Apr 16, 2024
CVE-2024-3333 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.12
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's message parameter in all versions up to, and including, 5.9.11 due to insufficient input sanitization and output escaping....
- Affected:
- up to 5.9.12
- Fixed in:
- 5.9.12
- Disclosed:
- Apr 9, 2024
CVE-2024-2623 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.12
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the alignment parameter in the Woo Product Carousel widget in all versions up to, and including, 5.9.10 due to insufficient input sanitization an...
- Affected:
- up to 5.9.12
- Fixed in:
- 5.9.12
- Disclosed:
- Apr 9, 2024
CVE-2024-2650 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.14
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated attackers to extract sensitive data including...
- Affected:
- up to 5.9.14
- Fixed in:
- 5.9.14
- Disclosed:
- Apr 9, 2024
CVE-2024-2974 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.14
unknown
[en] The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the "Login | Register Form" widget (disabled by default). This makes it possible for authenti...
- Affected:
- up to 5.9.14
- Fixed in:
- 5.9.14
- Disclosed:
- Mar 30, 2024
CVE-2024-3018 on NVD →
Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpassword
high
The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of untrusted input from the 'error_resetpassword' attribute of the "Login | Register Form" widget (disabled by default). This makes it possible for authenticated...
- CVSS:
- 8.8
- Affected:
- up to 5.9.13
- Fixed in:
- 5.9.14
- Disclosed:
- Mar 29, 2024
CVE-2024-3018 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 - Unauthenticated Sensitive Information Exposure
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated attackers to extract sensitive data including priva...
- CVSS:
- 5.3
- Affected:
- up to 5.9.13
- Fixed in:
- 5.9.14
- Disclosed:
- Mar 29, 2024
CVE-2024-2974 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the alignment parameter in the Woo Product Carousel widget in all versions up to, and including, 5.9.10 due to insufficient input sanitization and out...
- CVSS:
- 6.4
- Affected:
- up to 5.9.11
- Fixed in:
- 5.9.12
- Disclosed:
- Mar 25, 2024
CVE-2024-2650 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's message parameter in all versions up to, and including, 5.9.11 due to insufficient input sanitization and output escaping. This...
- CVSS:
- 6.4
- Affected:
- up to 5.9.11
- Fixed in:
- 5.9.12
- Disclosed:
- Mar 25, 2024
CVE-2024-2623 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.10
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Data Table widget in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user sup...
- Affected:
- up to 5.9.10
- Fixed in:
- 5.9.10
- Disclosed:
- Mar 13, 2024
CVE-2024-1537 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.10
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's event calendar widget in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user...
- Affected:
- up to 5.9.10
- Fixed in:
- 5.9.10
- Disclosed:
- Mar 13, 2024
CVE-2024-1536 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar
high
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's event calendar widget in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supp...
- CVSS:
- 7.4
- Affected:
- up to 5.9.9
- Fixed in:
- 5.9.10
- Disclosed:
- Mar 11, 2024
CVE-2024-1536 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Data Table widget in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied...
- CVSS:
- 6.4
- Affected:
- up to 5.9.9
- Fixed in:
- 5.9.10
- Disclosed:
- Mar 11, 2024
CVE-2024-1537 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.9
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery Widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. Th...
- Affected:
- up to 5.9.9
- Fixed in:
- 5.9.9
- Disclosed:
- Feb 20, 2024
CVE-2024-1171 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.9
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Filterable Controls label icon parameter in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escapi...
- Affected:
- up to 5.9.9
- Fixed in:
- 5.9.9
- Disclosed:
- Feb 20, 2024
CVE-2024-1236 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.9
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Content Ticker arrow attribute in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This m...
- Affected:
- up to 5.9.9
- Fixed in:
- 5.9.9
- Disclosed:
- Feb 20, 2024
CVE-2024-1276 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.9
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes...
- Affected:
- up to 5.9.9
- Fixed in:
- 5.9.9
- Disclosed:
- Feb 20, 2024
CVE-2024-1172 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Filterable Controls label icon parameter in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. T...
- CVSS:
- 6.4
- Affected:
- up to 5.9.8
- Fixed in:
- 5.9.9
- Disclosed:
- Feb 12, 2024
CVE-2024-1236 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Content Ticker arrow attribute in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes...
- CVSS:
- 6.4
- Affected:
- up to 5.9.8
- Fixed in:
- 5.9.9
- Disclosed:
- Feb 12, 2024
CVE-2024-1276 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it po...
- CVSS:
- 5.4
- Affected:
- up to 5.9.8
- Fixed in:
- 5.9.9
- Disclosed:
- Feb 12, 2024
CVE-2024-1172 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery Widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This ma...
- CVSS:
- 5.4
- Affected:
- up to 5.9.8
- Fixed in:
- 5.9.9
- Disclosed:
- Feb 12, 2024
CVE-2024-1171 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.5
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Login/Register Element in all versions up to, and including, 5.9.4 due to insufficient input sanitization and output escaping on the custom l...
- Affected:
- up to 5.9.5
- Fixed in:
- 5.9.5
- Disclosed:
- Feb 5, 2024
CVE-2024-0586 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.5
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 5.9.4 due to insufficient input sanitization and output escaping on...
- Affected:
- up to 5.9.5
- Fixed in:
- 5.9.5
- Disclosed:
- Feb 5, 2024
CVE-2024-0585 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.8
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting through editing context via the 'data-eael-wrapper-link' wrapper in all versions up to, and including, 5.9.7 due to insufficient input sanitization a...
- Affected:
- up to 5.9.8
- Fixed in:
- 5.9.8
- Disclosed:
- Feb 5, 2024
CVE-2024-0954 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting through editing context via the 'data-eael-wrapper-link' wrapper in all versions up to, and including, 5.9.7 due to insufficient input sanitization and ou...
- CVSS:
- 6.4
- Affected:
- up to 5.9.7
- Fixed in:
- 5.9.8
- Disclosed:
- Feb 1, 2024
CVE-2024-0954 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scritping
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Login/Register Element in all versions up to, and including, 5.9.4 due to insufficient input sanitization and output escaping on the custom login...
- CVSS:
- 6.4
- Affected:
- up to 5.9.4
- Fixed in:
- 5.9.5
- Disclosed:
- Jan 17, 2024
CVE-2024-0586 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 5.9.4 due to insufficient input sanitization and output escaping on the I...
- CVSS:
- 5.4
- Affected:
- up to 5.9.4
- Fixed in:
- 5.9.5
- Disclosed:
- Jan 17, 2024
CVE-2024-0585 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.3
unknown
[en] The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ID in all versions up to, and including, 5.9.2 due to insufficient input sanitization and output escaping. This makes it possible for auth...
- Affected:
- up to 5.9.3
- Fixed in:
- 5.9.3
- Disclosed:
- Jan 4, 2024
CVE-2023-7044 on NVD →
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ID in all versions up to, and including, 5.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authentic...
- CVSS:
- 6.4
- Affected:
- up to 5.9.2
- Fixed in:
- 5.9.3
- Disclosed:
- Jan 3, 2024
CVE-2023-7044 on NVD →
Essential Addons for Elementor <= 5.8.8 - Authenticated (Contributor+) Privilege Escalation
high
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 5.8.8 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Eleme...
- CVSS:
- 8.8
- Affected:
- up to 5.8.8
- Fixed in:
- 5.8.9
- Disclosed:
- Sep 14, 2023
CVE-2023-41955 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.8.9
unknown
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 5.8.8 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Eleme...
- Affected:
- up to 5.8.9
- Fixed in:
- 5.8.9
- Disclosed:
- Sep 14, 2023
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.8.2
unknown
[en] The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site'...
- Affected:
- up to 5.8.2
- Fixed in:
- 5.8.2
- Disclosed:
- Jul 20, 2023
CVE-2023-3779 on NVD →
Essential Addons For Elementor <=5.8.1 - Unauthenticated MailChimp API Key Disclosure
medium
The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's Mai...
- CVSS:
- 5.3
- Affected:
- up to 5.8.1
- Fixed in:
- 5.8.2
- Disclosed:
- Jul 19, 2023
CVE-2023-3779 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.7.2
unknown
[en] Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.
- Affected:
- up to 5.7.2
- Fixed in:
- 5.7.2
- Disclosed:
- May 12, 2023
CVE-2023-32243 on NVD →
Essential Addons for Elementor <= 5.7.1 - Unauthenticated Arbitrary Password Reset to Privilege Escalation
critical
The Essential Addons for Elementor plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Privilege Escalation in versions up to, and including, 5.7.1. This is due to a lack of validation of a password reset key in the reset_password function. This makes it possible for unauthenticated attac...
- CVSS:
- 9.8
- Affected:
- up to 5.7.1
- Fixed in:
- 5.7.2
- Disclosed:
- May 11, 2023
CVE-2023-32243 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.0.9
unknown
[en] The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the settings parameter found in the ~/includes/Traits/Helper.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user cli...
- Affected:
- up to 5.0.9
- Fixed in:
- 5.0.9
- Disclosed:
- Feb 24, 2022
CVE-2022-0683 on NVD →
Essential Addons for Elementor Lite <= 5.0.8 - Reflected Cross-Site Scripting
medium
The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the settings parameter found in the ~/includes/Traits/Helper.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks o...
- CVSS:
- 6.1
- Affected:
- up to 5.0.8
- Fixed in:
- 5.0.9
- Disclosed:
- Feb 18, 2022
CVE-2022-0683 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.0.9
unknown
[en] The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server, this could also lead to RCE via user up...
- Affected:
- up to 5.0.9
- Fixed in:
- 5.0.9
- Disclosed:
- Feb 1, 2022
CVE-2022-0320 on NVD →
Essential Addons for Elementor <= 5.0.4 - Local File Inclusion
critical
The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server, this could also lead to RCE via user uploade...
- CVSS:
- 9.8
- Affected:
- 1.0.0 – 5.0.4
- Fixed in:
- 5.0.5
- Disclosed:
- Jan 21, 2022
CVE-2022-0320 on NVD →
Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege Escalation
high
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Eleme...
- CVSS:
- 8.8
- Affected:
- up to 4.6.4
- Fixed in:
- 4.6.5
- Disclosed:
- May 5, 2021
CVE-2021-4447 on NVD →
Essential Addons for Elementor <= 4.6.4 - Missing Authorization
medium
The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized actio...
- CVSS:
- 6.3
- Affected:
- up to 4.6.4
- Fixed in:
- 4.6.5
- Disclosed:
- May 5, 2021
CVE-2021-4446 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 4.5.4
unknown
[en] The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, both via a similar method.
- Affected:
- up to 4.5.4
- Fixed in:
- 4.5.4
- Disclosed:
- May 5, 2021
CVE-2021-24255 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 4.6.5
unknown
The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized actio...
- Affected:
- up to 4.6.5
- Fixed in:
- 4.6.5
- Disclosed:
- May 5, 2021
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 4.6.5
unknown
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Eleme...
- Affected:
- up to 4.6.5
- Fixed in:
- 4.6.5
- Disclosed:
- May 5, 2021
Essential Addons for Elementor Lite <= 4.5.3 - Cross-Site Scripting
medium
The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, both via a similar method.
- CVSS:
- 5.4
- Affected:
- up to 4.5.4
- Fixed in:
- 4.5.4
- Disclosed:
- Apr 13, 2021
CVE-2021-24255 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 4.5.4
unknown
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress Essential Addons for Elementor plugin (versions <= 4.5.3).
- Affected:
- up to 4.5.4
- Fixed in:
- 4.5.4
- Disclosed:
- Apr 13, 2021
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.13
unknown
- Affected:
- up to 6.1.13
- Fixed in:
- 6.1.13
CVE-2024-9994 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.13
unknown
- Affected:
- up to 6.1.13
- Fixed in:
- 6.1.13
CVE-2024-9993 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.5
unknown
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...
- Affected:
- up to 6.0.5
- Fixed in:
- 6.0.5
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.20
unknown
- Affected:
- up to 6.1.20
- Fixed in:
- 6.1.20
CVE-2025-6244 on NVD →
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.2.3
unknown
- Affected:
- up to 6.2.3
- Fixed in:
- 6.2.3
CVE-2025-8451 on NVD →