plugin

Mega Elements Addons For Elementor Vulnerabilities

12 known security issues reported for the Mega Elements Addons For Elementor WordPress plugin. Most recent disclosed Sep 25, 2025.

6 medium

Running Mega Elements Addons For Elementor on your site? Check whether your installed version is affected.

Scan your site free

Mega Elements – Addons for Elementor <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer Widget

medium

The Mega Elements – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown Timer widget in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 1.3.2
Fixed in:
1.3.3
Disclosed:
Sep 25, 2025

CVE-2025-8200 on NVD →

Mega Elements &#8211; Addons for Elementor [mega-elements-addons-for-elementor] < 1.2.7

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kraftplugins Mega Elements allows Stored XSS.This issue affects Mega Elements: from n/a through 1.2.6.

Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Oct 24, 2024

CVE-2024-49693 on NVD →

Mega Elements <= 1.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...

CVSS:
6.4
Affected:
up to 1.2.6
Fixed in:
1.2.7
Disclosed:
Oct 21, 2024

CVE-2024-49693 on NVD →

Mega Elements &#8211; Addons for Elementor [mega-elements-addons-for-elementor] < 1.2.5

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kraftplugins Mega Elements allows Stored XSS.This issue affects Mega Elements: from n/a through 1.2.4.

Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Oct 6, 2024

CVE-2024-47343 on NVD →

Mega Elements <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...

CVSS:
6.4
Affected:
up to 1.2.4
Fixed in:
1.2.5
Disclosed:
Sep 27, 2024

CVE-2024-47343 on NVD →

Mega Elements &#8211; Addons for Elementor [mega-elements-addons-for-elementor] < 1.2.3

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kraftplugins Mega Elements.This issue affects Mega Elements: from n/a through 1.2.2.

Affected:
up to 1.2.3
Fixed in:
1.2.3
Disclosed:
Jul 21, 2024

CVE-2024-37466 on NVD →

Mega Elements <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...

CVSS:
6.4
Affected:
up to 1.2.2
Fixed in:
1.2.3
Disclosed:
Jul 1, 2024

CVE-2024-37466 on NVD →

Mega Elements &#8211; Addons for Elementor [mega-elements-addons-for-elementor] < 1.2.2

unknown

[en] The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor...

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
May 15, 2024

CVE-2024-4702 on NVD →

Mega Elements <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget

medium

The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-leve...

CVSS:
6.4
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
May 14, 2024

CVE-2024-4702 on NVD →

Mega Elements &#8211; Addons for Elementor [mega-elements-addons-for-elementor] < 1.2.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraftplugins Mega Elements allows Stored XSS.This issue affects Mega Elements: from n/a through 1.1.9.

Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Apr 18, 2024

CVE-2024-32575 on NVD →

Mega Elements <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a...

CVSS:
6.4
Affected:
up to 1.1.9
Fixed in:
1.2.0
Disclosed:
Apr 16, 2024

CVE-2024-32575 on NVD →

Mega Elements &#8211; Addons for Elementor [mega-elements-addons-for-elementor] < 1.3.3

unknown
Affected:
up to 1.3.3
Fixed in:
1.3.3

CVE-2025-8200 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database