plugin

Exclusive Addons For Elementor Vulnerabilities

59 known security issues reported for the Exclusive Addons For Elementor WordPress plugin. Most recent disclosed Aug 1, 2026.

31 medium

Running Exclusive Addons For Elementor on your site? Check whether your installed version is affected.

Scan your site free

Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image'

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-leve...

CVSS:
6.4
Affected:
up to 2.7.9.8
Fixed in:
2.7.9.9
Disclosed:
Aug 1, 2026

CVE-2026-12231 on NVD →

Exclusive Addons Elementor <= 2.8.0 - Unauthenticated Information Exposure

medium

The Exclusive Addons Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.8.0
Fixed in:
2.8.1
Disclosed:
Jul 27, 2026

CVE-2026-66438 on NVD →

Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access an...

CVSS:
6.4
Affected:
up to 2.7.9.8
Fixed in:
2.7.9.9
Disclosed:
Jul 6, 2026

CVE-2026-11328 on NVD →

Exclusive Addons for Elementor <= 2.7.9.9 - Unauthenticated Information Exposure

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.9.9. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.7.9.9
Fixed in:
2.8.0
Disclosed:
Jul 5, 2026

CVE-2026-59511 on NVD →

Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...

CVSS:
6.4
Affected:
up to 2.7.9.8
Fixed in:
2.7.9.9
Disclosed:
Jun 26, 2026

CVE-2026-57620 on NVD →

Exclusive Addons for Elementor <= 2.7.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget in all versions up to, and including, 2.7.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and ab...

CVSS:
6.4
Affected:
up to 2.7.9.4
Fixed in:
2.7.9.5
Disclosed:
Aug 5, 2025

CVE-2025-7498 on NVD →

Exclusive Addons for Elementor <= 2.7.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer Widget

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attributes of the Countdown Timer Widget in all versions up to, and including, 2.7.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Co...

CVSS:
6.4
Affected:
up to 2.7.9.1
Fixed in:
2.7.9.2
Disclosed:
May 26, 2025

CVE-2025-4783 on NVD →

Exclusive Addons Elementor <= 2.7.9 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Exclusive Addons Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scri...

CVSS:
4.4
Affected:
up to 2.7.9
Fixed in:
2.7.9.1
Disclosed:
May 19, 2025

CVE-2025-48244 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.7.9.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.

Affected:
up to 2.7.9.1
Fixed in:
2.7.9.1
Disclosed:
May 19, 2025

CVE-2025-48244 on NVD →

Exclusive Addons for Elementor <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Image Comparison Widgets

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Image Comparison Widgets in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...

CVSS:
6.4
Affected:
up to 2.7.6
Fixed in:
2.7.7
Disclosed:
Feb 27, 2025

CVE-2025-1571 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.7.5

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.4 via the render function in elements/tabs/tabs.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive pr...

Affected:
up to 2.7.5
Fixed in:
2.7.5
Disclosed:
Oct 29, 2024

CVE-2024-10312 on NVD →

Exclusive Addons for Elementor <= 2.7.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.4 via the render function in elements/tabs/tabs.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private...

CVSS:
4.3
Affected:
up to 2.7.4
Fixed in:
2.7.5
Disclosed:
Oct 28, 2024

CVE-2024-10312 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.7.2

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.7.1.

Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
Oct 17, 2024

CVE-2024-49292 on NVD →

Exclusive Addons Elementor <= 2.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Exclusive Addons Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web script...

CVSS:
6.4
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Oct 15, 2024

CVE-2024-49292 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.9

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Card widget in all versions up to, and including, 2.6.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...

Affected:
up to 2.6.9.9
Fixed in:
2.6.9.9
Disclosed:
Jun 26, 2024

CVE-2024-5332 on NVD →

Exclusive Addons for Elementor <= 2.6.9.8 - Authenticated (Contibutor+) Stored Cross-Site Scripting via Card Widget

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Card widget in all versions up to, and including, 2.6.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 2.6.9.8
Fixed in:
2.6.9.9
Disclosed:
Jun 25, 2024

CVE-2024-5332 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.7

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member widget in all versions up to, and including, 2.6.9.6 due to insufficient input sanitization and output escaping on user supplied 'url' attribute. This makes it possible for authenticated attacke...

Affected:
up to 2.6.9.7
Fixed in:
2.6.9.7
Disclosed:
May 15, 2024

CVE-2024-4618 on NVD →

Exclusive Addons for Elementor <= 2.6.9.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member widget in all versions up to, and including, 2.6.9.6 due to insufficient input sanitization and output escaping on user supplied 'url' attribute. This makes it possible for authenticated attackers, w...

CVSS:
6.4
Affected:
up to 2.6.9.6
Fixed in:
2.6.9.7
Disclosed:
May 14, 2024

CVE-2024-4618 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.2

unknown

[en] Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.1.

Affected:
up to 2.6.9.2
Fixed in:
2.6.9.2
Disclosed:
May 3, 2024

CVE-2024-33914 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.5

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Call to Action widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

Affected:
up to 2.6.9.5
Fixed in:
2.6.9.5
Disclosed:
May 2, 2024

CVE-2024-3985 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.4

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of the Button widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribu...

Affected:
up to 2.6.9.4
Fixed in:
2.6.9.4
Disclosed:
May 2, 2024

CVE-2024-2750 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.5

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Countdown Expired Title in all versions up to, and including, 2.6.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...

Affected:
up to 2.6.9.5
Fixed in:
2.6.9.5
Disclosed:
May 2, 2024

CVE-2024-3489 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.3

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exad_infobox_animating_mask_style’ parameter in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Affected:
up to 2.6.9.3
Fixed in:
2.6.9.3
Disclosed:
May 2, 2024

CVE-2024-2751 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.3

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid Widget in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping on user supplied tags. This makes it possible for authenticated attackers, with cont...

Affected:
up to 2.6.9.3
Fixed in:
2.6.9.3
Disclosed:
May 2, 2024

CVE-2024-2503 on NVD →

Exclusive Addons Elementor <= 2.6.9.1 - Missing Authorization to Post Duplication

medium

The Exclusive Addons Elementor plugin for WordPress is vulnerable to unauthorized access of datadue to an insufficient capability check on the duplicate_post() function in versions up to, and including, 2.6.9.1. This makes it possible for authenticated attackers, with contributor-level access and above, to duplicate ot...

CVSS:
5.4
Affected:
up to 2.6.9.1
Fixed in:
2.6.9.2
Disclosed:
Apr 29, 2024

CVE-2024-33914 on NVD →

Exclusive Addons for Elementor <= 2.6.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Call to Action

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Call to Action widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac...

CVSS:
6.4
Affected:
up to 2.6.9.4
Fixed in:
2.6.9.5
Disclosed:
Apr 22, 2024

CVE-2024-3985 on NVD →

Exclusive Addons for Elementor <= 2.6.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of the Button widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor a...

CVSS:
6.4
Affected:
up to 2.6.9.3
Fixed in:
2.6.9.4
Disclosed:
Apr 22, 2024

CVE-2024-2750 on NVD →

Exclusive Addons for Elementor <= 2.6.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Expired Title

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Countdown Expired Title in all versions up to, and including, 2.6.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 2.6.9.4
Fixed in:
2.6.9.5
Disclosed:
Apr 22, 2024

CVE-2024-3489 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.2.

Affected:
up to 2.6.9.3
Fixed in:
2.6.9.3
Disclosed:
Apr 16, 2024

CVE-2024-32557 on NVD →

Exclusive Addons for Elementor <= 2.6.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via InfoBox

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exad_infobox_animating_mask_style’ parameter in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with co...

CVSS:
6.4
Affected:
up to 2.6.9.2
Fixed in:
2.6.9.3
Disclosed:
Apr 15, 2024

CVE-2024-2751 on NVD →

Exclusive Addons for Elementor <= 2.6.9.2 - Authenticated(Contributor+) Stored Cross-Site Scripting via Post Grid

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid Widget in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping on user supplied tags. This makes it possible for authenticated attackers, with contribut...

CVSS:
6.4
Affected:
up to 2.6.9.2
Fixed in:
2.6.9.3
Disclosed:
Apr 15, 2024

CVE-2024-2503 on NVD →

Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout

medium

The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to opt-in or opt-out of tracking. This was patched in...

CVSS:
4.3
Affected:
up to 2.6.9
Fixed in:
2.6.9.1
Disclosed:
Apr 11, 2024

CVE-2024-32110 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.8.

Affected:
up to 2.6.9
Fixed in:
2.6.9
Disclosed:
Mar 27, 2024

CVE-2024-30177 on NVD →

Exclusive Addons Elementor <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Exclusive Addons Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web script...

CVSS:
6.4
Affected:
up to 2.6.9
Fixed in:
2.6.9.1
Disclosed:
Mar 26, 2024

CVE-2024-30232 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.

Affected:
up to 2.6.9.1
Fixed in:
2.6.9.1
Disclosed:
Mar 26, 2024

CVE-2024-30232 on NVD →

Exclusive Addons Elementor <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Exclusive Addons Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web script...

CVSS:
6.4
Affected:
up to 2.6.8
Fixed in:
2.6.9
Disclosed:
Mar 25, 2024

CVE-2024-30177 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.1

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acce...

Affected:
up to 2.6.9.1
Fixed in:
2.6.9.1
Disclosed:
Mar 13, 2024

CVE-2024-1413 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.1

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Covid-19 Stats Widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acces...

Affected:
up to 2.6.9.1
Fixed in:
2.6.9.1
Disclosed:
Mar 13, 2024

CVE-2024-2028 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.1

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to i...

Affected:
up to 2.6.9.1
Fixed in:
2.6.9.1
Disclosed:
Mar 13, 2024

CVE-2024-1234 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.1

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Action widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acces...

Affected:
up to 2.6.9.1
Fixed in:
2.6.9.1
Disclosed:
Mar 13, 2024

CVE-2024-1414 on NVD →

Exclusive Addons for Elementor <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Covid-19 Stats Widget

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Covid-19 Stats Widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...

CVSS:
6.4
Affected:
up to 2.6.9
Fixed in:
2.6.9.1
Disclosed:
Feb 29, 2024

CVE-2024-2028 on NVD →

Exclusive Addons for Elementor <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject...

CVSS:
6.4
Affected:
up to 2.6.9
Fixed in:
2.6.9.1
Disclosed:
Feb 29, 2024

CVE-2024-1234 on NVD →

Exclusive Addons for Elementor <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Call To Action Widget

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Action widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...

CVSS:
6.4
Affected:
up to 2.6.9
Fixed in:
2.6.9.1
Disclosed:
Feb 29, 2024

CVE-2024-1414 on NVD →

Exclusive Addons for Elementor <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer Widget

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access an...

CVSS:
6.4
Affected:
up to 2.6.9
Fixed in:
2.6.9.1
Disclosed:
Feb 29, 2024

CVE-2024-1413 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' url in carousels in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...

Affected:
up to 2.6.9
Fixed in:
2.6.9
Disclosed:
Feb 5, 2024

CVE-2024-0823 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9

unknown

[en] The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Anything functionality in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level...

Affected:
up to 2.6.9
Fixed in:
2.6.9
Disclosed:
Jan 27, 2024

CVE-2024-0824 on NVD →

Exclusive Addons for Elementor <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Link Anything

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Anything functionality in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acce...

CVSS:
6.4
Affected:
up to 2.6.8
Fixed in:
2.6.9
Disclosed:
Jan 26, 2024

CVE-2024-0824 on NVD →

Exclusive Addons for Elementor <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' url in carousels in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers w...

CVSS:
5.4
Affected:
up to 2.6.8
Fixed in:
2.6.9
Disclosed:
Jan 26, 2024

CVE-2024-0823 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9

unknown

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' url in carousels in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers w...

Affected:
up to 2.6.9
Fixed in:
2.6.9
Disclosed:
Jan 26, 2024

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9

unknown

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Anything functionality in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acce...

Affected:
up to 2.6.9
Fixed in:
2.6.9
Disclosed:
Jan 26, 2024

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in DevsCred Exclusive Addons Elementor plugin <= 2.6.1 versions.

Affected:
up to 2.6.2
Fixed in:
2.6.2
Disclosed:
Feb 2, 2023

CVE-2022-45067 on NVD →

Exclusive Addons for Elementor <= 2.6.1 - Cross-Site Request Forgery

medium

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.1. This is due to missing nonce validation on the uninstall_reason_submission() function. This makes it possible for unauthenticated attackers to submit uninstall reasons for the plu...

CVSS:
4.3
Affected:
up to 2.6.1
Fixed in:
2.6.2
Disclosed:
Jan 7, 2023

CVE-2022-45067 on NVD →

Appsero <= 1.2.1 - Missing Authorization

medium

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...

CVSS:
4.3
Affected:
up to 2.6.1
Fixed in:
2.6.2
Disclosed:
Dec 16, 2022

Appsero <= 1.2.0 - Cross-Site Request Forgery

medium

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...

CVSS:
4.3
Affected:
up to 2.6.1
Fixed in:
2.6.2
Disclosed:
Dec 14, 2022

CVE-2022-47150 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.7.9.5

unknown
Affected:
up to 2.7.9.5
Fixed in:
2.7.9.5

CVE-2025-7498 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.7.9.2

unknown
Affected:
up to 2.7.9.2
Fixed in:
2.7.9.2

CVE-2025-4783 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.7.7

unknown
Affected:
up to 2.7.7
Fixed in:
2.7.7

CVE-2025-1571 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.9.1

unknown
Affected:
up to 2.6.9.1
Fixed in:
2.6.9.1

CVE-2024-32110 on NVD →

Exclusive Addons for Elementor [exclusive-addons-for-elementor] < 2.6.2

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 2.6.2
Fixed in:
2.6.2

CVE-2022-47150 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database