Magical Addons For Elementor <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scri...
- CVSS:
- 6.4
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.2
- Disclosed:
- Mar 1, 2026
CVE-2026-32429 on NVD →
Magical Addons For Elementor <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes
medium
The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wi...
- CVSS:
- 6.4
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.9
- Disclosed:
- Jul 28, 2025
CVE-2025-8196 on NVD →
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) [magical-addons-for-elementor] <= 1.3.6 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.2.6.
- Affected:
- up to 1.3.6
- Fix:
- No patched version reported
- Disclosed:
- Dec 6, 2024
CVE-2024-54212 on NVD →
Magical Addons For Elementor <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scri...
- CVSS:
- 6.4
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.7
- Disclosed:
- Dec 2, 2024
CVE-2024-54212 on NVD →
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) [magical-addons-for-elementor] < 1.2.5
unknown
[en] The Magical Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the get_content_type function in includes/widgets/content-reveal.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to...
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Nov 9, 2024
CVE-2024-10352 on NVD →
Magical Addons For Elementor <= 1.2.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template
medium
The Magical Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the get_content_type function in includes/widgets/content-reveal.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extr...
- CVSS:
- 4.3
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.5
- Disclosed:
- Nov 8, 2024
CVE-2024-10352 on NVD →
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) [magical-addons-for-elementor] < 1.2.3
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through 1.2.1.
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Nov 4, 2024
CVE-2024-51665 on NVD →
Magical Addons For Elementor <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to ma...
- CVSS:
- 6.4
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.3
- Disclosed:
- Nov 1, 2024
CVE-2024-51665 on NVD →
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) [magical-addons-for-elementor] < 1.1.42
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor.This issue affects Magical Addons For Elementor: from n/a through 1.1.41.
- Affected:
- up to 1.1.42
- Fixed in:
- 1.1.42
- Disclosed:
- Jul 22, 2024
CVE-2024-38730 on NVD →
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) [magical-addons-for-elementor] < 1.1.42
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.1.41.
- Affected:
- up to 1.1.42
- Fixed in:
- 1.1.42
- Disclosed:
- Jul 20, 2024
CVE-2024-38681 on NVD →
Magical Addons For Elementor <= 1.1.41 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.41. This makes it possible for authenticated attackers, with Subscriber-level access and above, to m...
- CVSS:
- 6.4
- Affected:
- up to 1.1.41
- Fixed in:
- 1.1.42
- Disclosed:
- Jul 11, 2024
CVE-2024-38730 on NVD →
Magical Addons For Elementor <= 1.1.41 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.41 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 1.1.41
- Fixed in:
- 1.1.42
- Disclosed:
- Jul 10, 2024
CVE-2024-38681 on NVD →
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) [magical-addons-for-elementor] < 1.1.40
unknown
[en] The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 1.1.39 due to insufficient input sanitization and output escaping. This mak...
- Affected:
- up to 1.1.40
- Fixed in:
- 1.1.40
- Disclosed:
- Jun 6, 2024
CVE-2024-5161 on NVD →
Magical Addons For Elementor <= 1.1.39 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 1.1.39 due to insufficient input sanitization and output escaping. This makes it...
- CVSS:
- 6.4
- Affected:
- up to 1.1.39
- Fixed in:
- 1.1.40
- Disclosed:
- Jun 5, 2024
CVE-2024-5161 on NVD →
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) [magical-addons-for-elementor] < 1.1.38
unknown
[en] The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including, 1.1.37 due to insufficient input sanitization and output escapi...
- Affected:
- up to 1.1.38
- Fixed in:
- 1.1.38
- Disclosed:
- May 9, 2024
CVE-2024-2923 on NVD →
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) [magical-addons-for-elementor] < 1.1.35
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.1.34.
- Affected:
- up to 1.1.35
- Fixed in:
- 1.1.35
- Disclosed:
- May 8, 2024
CVE-2024-34547 on NVD →
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) <= 1.1.34 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 1.1.35 (exclusive) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above,...
- CVSS:
- 4.3
- Affected:
- up to 1.1.34
- Fixed in:
- 1.1.35
- Disclosed:
- May 7, 2024
CVE-2024-34547 on NVD →
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) <= 1.1.37 - Authenticated (Contributor+) Stored Cross-Site Scripting via Text Effect Widget
medium
The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including, 1.1.37 due to insufficient input sanitization and output escaping on...
- CVSS:
- 6.4
- Affected:
- up to 1.1.37
- Fixed in:
- 1.1.38
- Disclosed:
- May 6, 2024
CVE-2024-2923 on NVD →
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) [magical-addons-for-elementor] < 1.3.9
unknown
- Affected:
- up to 1.3.9
- Fixed in:
- 1.3.9
CVE-2025-8196 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database