plugin

Sky Elementor Addons Vulnerabilities

19 known security issues reported for the Sky Elementor Addons WordPress plugin. Most recent disclosed May 7, 2026.

2 high 8 medium

Running Sky Elementor Addons on your site? Check whether your installed version is affected.

Scan your site free

Sky Addons <= 3.3.2 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Script

medium

The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom post type in all versions up to, and including, 3.3.2. This is due to the custom post type being registered with `capability_type => 'post'` and `show_in_rest => true`, combined with insufficient input s...

CVSS:
6.4
Affected:
up to 3.3.2
Fixed in:
3.3.3
Disclosed:
May 7, 2026

CVE-2026-7475 on NVD →

Sky Addons for Elementor <= 3.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

medium

The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple widgets in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-lev...

CVSS:
6.4
Affected:
up to 3.1.4
Fixed in:
3.2.0
Disclosed:
Jul 28, 2025

CVE-2025-8216 on NVD →

Sky Addons – Elementor Addons with Widgets &amp; Templates [sky-elementor-addons] < 3.0.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wowDevs Sky Addons for Elementor allows Stored XSS. This issue affects Sky Addons for Elementor: from n/a through 3.0.1.

Affected:
up to 3.0.3
Fixed in:
3.0.3
Disclosed:
Apr 24, 2025

CVE-2025-46260 on NVD →

Sky Addons for Elementor <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 3.0.1
Fixed in:
3.0.3
Disclosed:
Apr 22, 2025

CVE-2025-46260 on NVD →

Sky Addons – Elementor Addons with Widgets &amp; Templates [sky-elementor-addons] < 2.6.2

unknown

[en] The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to missing or incorrect nonce validation o...

Affected:
up to 2.6.2
Fixed in:
2.6.2
Disclosed:
Nov 22, 2024

CVE-2024-11601 on NVD →

Sky Addons – Elementor Addons with Widgets &amp; Templates [sky-elementor-addons] < 2.6.3

unknown

[en] The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the save_options() function in a...

Affected:
up to 2.6.3
Fixed in:
2.6.3
Disclosed:
Nov 22, 2024

CVE-2024-11104 on NVD →

Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) <= 2.6.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update

high

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the save_options() function in all ve...

CVSS:
8.1
Affected:
up to 2.6.2
Fixed in:
2.6.3
Disclosed:
Nov 21, 2024

CVE-2024-11104 on NVD →

Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) <= 2.6.1 - Cross-Site Request Forgery to Limited Arbitrary Options Update

high

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to missing or incorrect nonce validation on the...

CVSS:
8.1
Affected:
up to 2.6.1
Fixed in:
2.6.2
Disclosed:
Nov 21, 2024

CVE-2024-11601 on NVD →

Sky Addons – Elementor Addons with Widgets &amp; Templates [sky-elementor-addons] < 2.6.2

unknown

[en] The Sky Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the render function in modules/content-switcher/widgets/content-switcher.php. This makes it possible for authenticated attackers, with Contributor-level access and above...

Affected:
up to 2.6.2
Fixed in:
2.6.2
Disclosed:
Nov 21, 2024

CVE-2024-9542 on NVD →

Sky Addons for Elementor <= 2.6.1 - Authenticated (Contributor+) Sensitive Information Exposure via Content Switcher Widget Elementor Template

medium

The Sky Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the render function in modules/content-switcher/widgets/content-switcher.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to...

CVSS:
4.3
Affected:
up to 2.6.1
Fixed in:
2.6.2
Disclosed:
Nov 20, 2024

CVE-2024-9542 on NVD →

Sky Addons – Elementor Addons with Widgets &amp; Templates [sky-elementor-addons] < 2.5.16

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wowDevs Sky Addons for Elementor allows Stored XSS.This issue affects Sky Addons for Elementor: from n/a through 2.5.15.

Affected:
up to 2.5.16
Fixed in:
2.5.16
Disclosed:
Oct 28, 2024

CVE-2024-50433 on NVD →

Sky Addons for Elementor <= 2.5.15 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 2.5.15
Fixed in:
2.5.16
Disclosed:
Oct 24, 2024

CVE-2024-50433 on NVD →

Sky Addons – Elementor Addons with Widgets &amp; Templates [sky-elementor-addons] < 2.5.12

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wowDevs Sky Addons for Elementor allows Stored XSS.This issue affects Sky Addons for Elementor: from n/a through 2.5.11.

Affected:
up to 2.5.12
Fixed in:
2.5.12
Disclosed:
Oct 6, 2024

CVE-2024-47332 on NVD →

Sky Addons for Elementor <= 2.5.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 2.5.11
Fixed in:
2.5.12
Disclosed:
Sep 26, 2024

CVE-2024-47332 on NVD →

Sky Addons – Elementor Addons with Widgets &amp; Templates [sky-elementor-addons] < 2.5.6

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Techfyd Sky Addons for Elementor allows Stored XSS.This issue affects Sky Addons for Elementor: from n/a through 2.5.5.

Affected:
up to 2.5.6
Fixed in:
2.5.6
Disclosed:
Jul 20, 2024

CVE-2024-38687 on NVD →

Sky Addons for Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 2.5.5
Fixed in:
2.5.6
Disclosed:
Jul 10, 2024

CVE-2024-38687 on NVD →

Sky Addons – Elementor Addons with Widgets &amp; Templates [sky-elementor-addons] < 2.5.0

unknown

[en] The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link URL value in all versions up to, and including, 2.4.0 due to insufficient input sanitization and o...

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Mar 13, 2024

CVE-2024-2286 on NVD →

Sky Addons for Elementor <= 2.4.0 - Authenticated(Contributor+) Stored Cross-site scripting via Wrapper Link URL

medium

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link URL value in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output...

CVSS:
6.4
Affected:
up to 2.4.0
Fixed in:
2.5.0
Disclosed:
Mar 12, 2024

CVE-2024-2286 on NVD →

Sky Addons – Elementor Addons with Widgets &amp; Templates [sky-elementor-addons] < 3.2.0

unknown
Affected:
up to 3.2.0
Fixed in:
3.2.0

CVE-2025-8216 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database