plugin

Powerpack Lite For Elementor Vulnerabilities

25 known security issues reported for the Powerpack Lite For Elementor WordPress plugin. Most recent disclosed Mar 1, 2026.

13 medium

Running Powerpack Lite For Elementor on your site? Check whether your installed version is affected.

Scan your site free

PowerPack Addons for Elementor <= 2.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web sc...

CVSS:
6.4
Affected:
up to 2.9.9
Fixed in:
2.9.10
Disclosed:
Mar 1, 2026

CVE-2026-32430 on NVD →

PowerPack Lite for Elementor <= 2.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting Via 'cursor_url'

medium

The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor_url’ parameter in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...

CVSS:
6.4
Affected:
up to 2.9.4
Fixed in:
2.9.5
Disclosed:
Sep 9, 2025

CVE-2025-8388 on NVD →

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Cursor Extension in all versions up to, and including, 2.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...

CVSS:
6.4
Affected:
up to 2.9.0
Fixed in:
2.9.1
Disclosed:
Mar 31, 2025

CVE-2025-1512 on NVD →

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) [powerpack-lite-for-elementor] < 2.8.2

unknown

[en] The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 via the Content Reveal widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated atta...

Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Dec 6, 2024

CVE-2024-10692 on NVD →

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) <= 2.8.1 - Authenticated (Contributor+) Post Disclosure

medium

The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 via the Content Reveal widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers...

CVSS:
4.3
Affected:
up to 2.8.1
Fixed in:
2.8.2
Disclosed:
Dec 5, 2024

CVE-2024-10692 on NVD →

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) [powerpack-lite-for-elementor] < 2.7.21

unknown

[en] The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's Link Effects widget in all versions up to, and including, 2.7.20 due to insufficient input sanitization and output escaping. This...

Affected:
up to 2.7.21
Fixed in:
2.7.21
Disclosed:
Jun 13, 2024

CVE-2024-5787 on NVD →

PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) <= 2.7.20 - Authenticated (Contributor+) Stored Cross-Site Scripting via Link Effects Widget

medium

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's Link Effects widget in all versions up to, and including, 2.7.20 due to insufficient input sanitization and output escaping. This make...

CVSS:
6.4
Affected:
up to 2.7.20
Fixed in:
2.7.21
Disclosed:
Jun 12, 2024

CVE-2024-5787 on NVD →

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) [powerpack-lite-for-elementor] < 2.7.20

unknown

[en] The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘pp_animated_gradient_bg_color’ parameter in all versions up to, and including, 2.7.19 due to insufficient input sanitization and output escaping. This mak...

Affected:
up to 2.7.20
Fixed in:
2.7.20
Disclosed:
May 30, 2024

CVE-2024-5327 on NVD →

PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) <= 2.7.19 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

medium

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘pp_animated_gradient_bg_color’ parameter in all versions up to, and including, 2.7.19 due to insufficient input sanitization and output escaping. This makes it...

CVSS:
6.4
Affected:
up to 2.7.19
Fixed in:
2.7.20
Disclosed:
May 29, 2024

CVE-2024-5327 on NVD →

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) [powerpack-lite-for-elementor] < 2.7.19

unknown

[en] The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Tweet widget in all versions up to, and including, 2.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acces...

Affected:
up to 2.7.19
Fixed in:
2.7.19
Disclosed:
Apr 9, 2024

CVE-2024-2492 on NVD →

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) [powerpack-lite-for-elementor] < 2.7.18

unknown

[en] The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the *_html_tag* attribute of multiple widgets in all versions up to, and including, 2.7.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with co...

Affected:
up to 2.7.18
Fixed in:
2.7.18
Disclosed:
Mar 30, 2024

CVE-2024-2491 on NVD →

PowerPack Addons for Elementor <= 2.7.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Tweet Widget

medium

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Tweet widget in all versions up to, and including, 2.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...

CVSS:
6.4
Affected:
up to 2.7.18
Fixed in:
2.7.19
Disclosed:
Mar 29, 2024

CVE-2024-2492 on NVD →

PowerPack Addons for Elementor <= 2.7.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via *_html_tag*

medium

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the *_html_tag* attribute of multiple widgets in all versions up to, and including, 2.7.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contrib...

CVSS:
6.4
Affected:
up to 2.7.17
Fixed in:
2.7.18
Disclosed:
Mar 29, 2024

CVE-2024-2491 on NVD →

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) [powerpack-lite-for-elementor] < 2.7.16

unknown

[en] The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the settings of the Twitter Buttons Widget in all versions up to, and including, 2.7.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contr...

Affected:
up to 2.7.16
Fixed in:
2.7.16
Disclosed:
Feb 20, 2024

CVE-2024-1411 on NVD →

PowerPack Addons for Elementor <= 2.7.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Buttons Widget

medium

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the settings of the Twitter Buttons Widget in all versions up to, and including, 2.7.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributo...

CVSS:
6.4
Affected:
up to 2.7.15
Fixed in:
2.7.16
Disclosed:
Feb 15, 2024

CVE-2024-1411 on NVD →

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) [powerpack-lite-for-elementor] < 2.7.15

unknown

[en] The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's buttons in all versions up to, and including, 2.7.14 due to insufficient input sanitization and output escaping on user supplied URL values. This makes it p...

Affected:
up to 2.7.15
Fixed in:
2.7.15
Disclosed:
Feb 7, 2024

CVE-2024-1055 on NVD →

PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) <= 2.7.14 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's buttons in all versions up to, and including, 2.7.14 due to insufficient input sanitization and output escaping on user supplied URL values. This makes it possib...

CVSS:
5.4
Affected:
up to 2.7.14
Fixed in:
2.7.15
Disclosed:
Feb 6, 2024

CVE-2024-1055 on NVD →

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) [powerpack-lite-for-elementor] < 2.7.14

unknown

[en] The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.13. This is due to missing or incorrect nonce validation in the powerpack-lite-for-elementor/classes/class-pp-admin-settings.php fil...

Affected:
up to 2.7.14
Fixed in:
2.7.14
Disclosed:
Jan 3, 2024

CVE-2023-6984 on NVD →

PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) <= 2.7.13 - Cross-Site Request Forgery

medium

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.13. This is due to missing or incorrect nonce validation in the powerpack-lite-for-elementor/classes/class-pp-admin-settings.php file. Th...

CVSS:
5.3
Affected:
up to 2.7.13
Fixed in:
2.7.14
Disclosed:
Jan 2, 2024

CVE-2023-6984 on NVD →

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) [powerpack-lite-for-elementor] < 2.6.2

unknown

[en] The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 2.6.2
Fixed in:
2.6.2
Disclosed:
Jan 3, 2022

CVE-2021-25027 on NVD →

PowerPack Addons for Elementor <= 2.6.1 - Reflected Cross-Site Scripting

medium

The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 2.6.1
Fixed in:
2.6.2
Disclosed:
Dec 6, 2021

CVE-2021-25027 on NVD →

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) [powerpack-lite-for-elementor] < 2.3.2

unknown

[en] The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
May 5, 2021

CVE-2021-24263 on NVD →

PowerPack Addons for Elementor <= 2.3.1 - Contributor+ Stored Cross-Site Scripting

medium

The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVSS:
5.4
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Apr 13, 2021

CVE-2021-24263 on NVD →

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) [powerpack-lite-for-elementor] < 2.3.2

unknown

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress PowerPack Addons for Elementor plugin (versions <= 2.3.1).

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Apr 13, 2021

PowerPack Elementor Addons (Free Widgets, Extensions and Templates) [powerpack-lite-for-elementor] < 2.9.1

unknown
Affected:
up to 2.9.1
Fixed in:
2.9.1

CVE-2025-1512 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database