The Plus Addons for Elementor <= 6.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' Parameter
medium
The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions up to, and including, 6.4.15 This is due to insufficient output escaping in the render() function, where the carousel_direction value is plac...
- CVSS:
- 6.4
- Affected:
- up to 6.4.15
- Fixed in:
- 6.4.16
- Disclosed:
- May 28, 2026
CVE-2026-9243 on NVD →
The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes
medium
The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting via the Button widget's `custom_attributes` setting in versions up to and including 6.4.11. The `render` function in `modules/widgets/tp_button.php` passed the raw `custom_attributes` string thr...
- CVSS:
- 6.4
- Affected:
- up to 6.4.11
- Fixed in:
- 6.4.12
- Disclosed:
- May 21, 2026
CVE-2026-15285 on NVD →
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...
- CVSS:
- 6.4
- Affected:
- up to 6.4.11
- Fixed in:
- 6.4.12
- Disclosed:
- May 21, 2026
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...
- CVSS:
- 6.4
- Affected:
- up to 6.4.11
- Fixed in:
- 6.4.12
- Disclosed:
- May 21, 2026
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite Widget
medium
The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to stored cross-site scripting via the `menu_hover_click` parameter of the Navigation Menu Lite widget in all versions up to, and including, 6.4.11 due to insufficient input sanit...
- CVSS:
- 6.4
- Affected:
- up to 6.4.11
- Fixed in:
- 6.4.12
- Disclosed:
- May 13, 2026
CVE-2026-5243 on NVD →
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar
medium
The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Progress Bar shortcode in all versions up to, and including, 6.4.9 due to insufficient input sanitization and output escaping on us...
- CVSS:
- 6.4
- Affected:
- up to 6.4.9
- Fixed in:
- 6.4.10
- Disclosed:
- Apr 7, 2026
CVE-2026-3311 on NVD →
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay
medium
The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.4.7. This is due to the plugin decrypting and trusting attacker-controlled email_data in...
- CVSS:
- 5.3
- Affected:
- up to 6.4.7
- Fixed in:
- 6.4.8
- Disclosed:
- Feb 21, 2026
CVE-2026-2385 on NVD →
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type'
medium
The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 6.4.7. This is due to the tpae_create_page() AJAX handler authorizing users only with current_user_can('edit_posts...
- CVSS:
- 4.3
- Affected:
- up to 6.4.7
- Fixed in:
- 6.4.8
- Disclosed:
- Feb 18, 2026
CVE-2026-2386 on NVD →
The Plus Addons for Elementor <= 6.3.15 - Authenticated (Author+) Stored Cross-Site Scripting via SVG
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.3.15 due to insufficient input sanitization and output escaping. This makes it possible for...
- CVSS:
- 6.4
- Affected:
- up to 6.3.15
- Fixed in:
- 6.3.16
- Disclosed:
- Sep 22, 2025
CVE-2025-9698 on NVD →
The Plus Addons for Elementor Page Builder Lite <= 6.3.13 - Missing Authorization
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.3.13. This makes it possible for authenticated attackers, with Contribut...
- CVSS:
- 4.3
- Affected:
- up to 6.3.13
- Fixed in:
- 6.3.14
- Disclosed:
- Aug 14, 2025
CVE-2025-55712 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.3.14
unknown
[en] Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 6.3.13.
- Affected:
- up to 6.3.14
- Fixed in:
- 6.3.14
- Disclosed:
- Aug 14, 2025
CVE-2025-55712 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom script parameter in all versions up to, and including, 6.3.10 even when the user does not have the unfiltered_html capability. This makes...
- CVSS:
- 6.4
- Affected:
- up to 6.3.10
- Fixed in:
- 6.3.11
- Disclosed:
- Jul 31, 2025
CVE-2025-7646 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.2.8
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Innovations The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 6.2.7.
- Affected:
- up to 6.2.8
- Fixed in:
- 6.2.8
- Disclosed:
- Jun 6, 2025
CVE-2025-49076 on NVD →
The Plus Addons for Elementor Page Builder Lite <= 6.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject...
- CVSS:
- 6.4
- Affected:
- up to 6.2.7
- Fixed in:
- 6.2.8
- Disclosed:
- May 30, 2025
CVE-2025-49076 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown, Syntax Highlighter, and Page Scroll widgets in all versions up to, and including, 6.2.2 due to insufficient input sanitization and ou...
- CVSS:
- 6.4
- Affected:
- up to 6.2.2
- Fixed in:
- 6.2.3
- Disclosed:
- Mar 7, 2025
CVE-2025-1287 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.2.0
unknown
[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table Widget's searchable_label parameter in all versions up to, and including, 6.1.8 due to insufficient input sanitization and output esc...
- Affected:
- up to 6.2.0
- Fixed in:
- 6.2.0
- Disclosed:
- Feb 1, 2025
CVE-2024-11829 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table Widget's searchable_label parameter in all versions up to, and including, 6.1.8 due to insufficient input sanitization and output escaping...
- CVSS:
- 6.4
- Affected:
- up to 6.1.8
- Fixed in:
- 6.2.0
- Disclosed:
- Jan 31, 2025
CVE-2024-11829 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.0.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows DOM-Based XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.6.14.
- Affected:
- up to 6.0.1
- Fixed in:
- 6.0.1
- Disclosed:
- Dec 6, 2024
CVE-2024-53823 on NVD →
The Plus Addons for Elementor Page Builder Lite <= 5.6.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to injec...
- CVSS:
- 6.4
- Affected:
- up to 5.6.14
- Fixed in:
- 6.0.1
- Disclosed:
- Dec 2, 2024
CVE-2024-53823 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.0.4
unknown
[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.3 via the render function in modules/widgets/tp_carousel_anything.php, modules/widgets/tp_page_scroll....
- Affected:
- up to 6.0.4
- Fixed in:
- 6.0.4
- Disclosed:
- Nov 20, 2024
CVE-2024-10365 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.0.3 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.3 via the render function in modules/widgets/tp_carousel_anything.php, modules/widgets/tp_page_scroll.php,...
- CVSS:
- 4.3
- Affected:
- up to 6.0.3
- Fixed in:
- 6.0.4
- Disclosed:
- Nov 19, 2024
CVE-2024-10365 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3
unknown
[en] Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.6.2.
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.3
- Disclosed:
- Nov 1, 2024
CVE-2024-43932 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.12
unknown
[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.11 via the render function in modules/widgets/tp_accordion.php. This makes it possible for authenticat...
- Affected:
- up to 5.6.12
- Fixed in:
- 5.6.12
- Disclosed:
- Oct 11, 2024
CVE-2024-8913 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_template
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.11 via the render function in modules/widgets/tp_accordion.php. This makes it possible for authenticated at...
- CVSS:
- 4.3
- Affected:
- up to 5.6.11
- Fixed in:
- 5.6.12
- Disclosed:
- Oct 10, 2024
CVE-2024-8913 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.6.2.
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.3
- Disclosed:
- Sep 17, 2024
CVE-2024-43977 on NVD →
The Plus Addons for Elementor Page Builder Lite <= 5.6.2 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbi...
- CVSS:
- 6.4
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.3
- Disclosed:
- Aug 28, 2024
CVE-2024-43977 on NVD →
The Plus Addons for Elementor Page Builder Lite <= 5.6.2 - Missing Authorization
medium
The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in the /includes/plus-options/extension/cmb2-field-ajax-search.php file in versions up to, and including, 5.6.2. This makes it possible for authenticated attackers, wit...
- CVSS:
- 4.3
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.3
- Disclosed:
- Aug 26, 2024
CVE-2024-43932 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3
unknown
[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the carousel_direction parameter of testimonials widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization and...
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.3
- Disclosed:
- Aug 22, 2024
CVE-2024-5583 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonials Widget Settings
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the carousel_direction parameter of testimonials widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization and outpu...
- CVSS:
- 6.4
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.3
- Disclosed:
- Aug 21, 2024
CVE-2024-5583 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3
unknown
[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_date attribute within the plugin's Video widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization an...
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.3
- Disclosed:
- Aug 20, 2024
CVE-2024-5763 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3
unknown
[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘res_width_value’ parameter within the plugin's tp_page_scroll widget in all versions up to, and including, 5.6.2 due to insufficient input...
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.3
- Disclosed:
- Aug 20, 2024
CVE-2024-6575 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_date attribute within the plugin's Video widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization and out...
- CVSS:
- 6.4
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.3
- Disclosed:
- Aug 19, 2024
CVE-2024-5763 on NVD →
The Plus Addons for Elementor <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via TP Page Scroll Widget
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘res_width_value’ parameter within the plugin's tp_page_scroll widget in all versions up to, and including, 5.6.2 due to insufficient input sani...
- CVSS:
- 6.4
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.3
- Disclosed:
- Aug 19, 2024
CVE-2024-6575 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.2
unknown
[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied...
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.2
- Disclosed:
- Jul 3, 2024
CVE-2024-4482 on NVD →
The Plus Addons for Elementor <= 5.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied 'text...
- CVSS:
- 6.4
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.2
- Disclosed:
- Jul 2, 2024
CVE-2024-4482 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.1
unknown
[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘video_color’ parameter in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes...
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.1
- Disclosed:
- Jun 27, 2024
CVE-2024-4983 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.0- Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘video_color’ parameter in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes it po...
- CVSS:
- 6.4
- Affected:
- up to 5.6.0
- Fixed in:
- 5.6.1
- Disclosed:
- Jun 26, 2024
CVE-2024-4983 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.5
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.5.4.
- Affected:
- up to 5.5.5
- Fixed in:
- 5.5.5
- Disclosed:
- Jun 8, 2024
CVE-2024-35709 on NVD →
The Plus Addons for Elementor Page Builder Lite <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject...
- CVSS:
- 6.4
- Affected:
- up to 5.5.4
- Fixed in:
- 5.5.5
- Disclosed:
- Jun 6, 2024
CVE-2024-35709 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.5
unknown
[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Hover Card widget in all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- Affected:
- up to 5.5.5
- Fixed in:
- 5.5.5
- Disclosed:
- May 24, 2024
CVE-2024-2784 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.3
unknown
[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘xai_username’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. This makes it...
- Affected:
- up to 5.5.3
- Fixed in:
- 5.5.3
- Disclosed:
- May 24, 2024
CVE-2024-4484 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.5
unknown
[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers...
- Affected:
- up to 5.5.5
- Fixed in:
- 5.5.5
- Disclosed:
- May 24, 2024
CVE-2024-3718 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.3
unknown
[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_custom_attributes’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. Th...
- Affected:
- up to 5.5.3
- Fixed in:
- 5.5.3
- Disclosed:
- May 24, 2024
CVE-2024-4485 on NVD →
The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pricing Table, & Flip Box
medium
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wit...
- CVSS:
- 6.4
- Affected:
- up to 5.5.4
- Fixed in:
- 5.5.5
- Disclosed:
- May 23, 2024
CVE-2024-3718 on NVD →
The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contibutor+) Stored Cross-Site Scripting via Hover Card
medium
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Hover Card widget in all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...
- CVSS:
- 6.4
- Affected:
- up to 5.5.4
- Fixed in:
- 5.5.5
- Disclosed:
- May 23, 2024
CVE-2024-2784 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_custom_attributes’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. This ma...
- CVSS:
- 6.4
- Affected:
- up to 5.5.2
- Fixed in:
- 5.5.3
- Disclosed:
- May 23, 2024
CVE-2024-4485 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘xai_username’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. This makes it possi...
- CVSS:
- 6.4
- Affected:
- up to 5.5.1
- Fixed in:
- 5.5.3
- Disclosed:
- May 23, 2024
CVE-2024-4484 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0
unknown
[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with co...
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.0
- Disclosed:
- May 9, 2024
CVE-2024-2785 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0
unknown
[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access...
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.0
- Disclosed:
- May 9, 2024
CVE-2024-0445 on NVD →
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or hi...
- CVSS:
- 6.4
- Affected:
- up to 5.4.2
- Fixed in:
- 5.5.0
- Disclosed:
- May 6, 2024
CVE-2024-0445 on NVD →
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate
medium
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contrib...
- CVSS:
- 6.4
- Affected:
- up to 5.4.2
- Fixed in:
- 5.5.0
- Disclosed:
- May 6, 2024
CVE-2024-2785 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.4.2.
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.0
- Disclosed:
- May 6, 2024
CVE-2024-34373 on NVD →
The Plus Addons for Elementor Page Builder Lite <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject...
- CVSS:
- 6.4
- Affected:
- up to 5.4.2
- Fixed in:
- 5.5.0
- Disclosed:
- May 3, 2024
CVE-2024-34373 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0
unknown
[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher,...
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.0
- Disclosed:
- May 2, 2024
CVE-2024-3199 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0
unknown
[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in the plugin's widgets in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.0
- Disclosed:
- May 2, 2024
CVE-2024-3197 on NVD →
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
medium
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to i...
- CVSS:
- 6.4
- Affected:
- up to 5.4.2
- Fixed in:
- 5.5.0
- Disclosed:
- Apr 25, 2024
CVE-2024-3199 on NVD →
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes
medium
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in the plugin's widgets in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...
- CVSS:
- 6.4
- Affected:
- up to 5.4.2
- Fixed in:
- 5.5.0
- Disclosed:
- Apr 25, 2024
CVE-2024-3197 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.4.2
unknown
[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Team Member Listing widget. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the ser...
- Affected:
- up to 5.4.2
- Fixed in:
- 5.4.2
- Disclosed:
- Mar 27, 2024
CVE-2024-2210 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.4.2
unknown
[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Clients widget. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowin...
- Affected:
- up to 5.4.2
- Fixed in:
- 5.4.2
- Disclosed:
- Mar 27, 2024
CVE-2024-2203 on NVD →
The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Clients Widget
medium
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Clients widget. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the...
- CVSS:
- 6.4
- Affected:
- up to 5.4.1
- Fixed in:
- 5.4.2
- Disclosed:
- Mar 26, 2024
CVE-2024-2203 on NVD →
The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Team Member Listing
medium
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Team Member Listing widget. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server,...
- CVSS:
- 6.4
- Affected:
- up to 5.4.1
- Fixed in:
- 5.4.2
- Disclosed:
- Mar 26, 2024
CVE-2024-2210 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.4.1
unknown
[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ attribute of the Header Meta Content widget in all versions up to, and including, 5.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w...
- Affected:
- up to 5.4.1
- Fixed in:
- 5.4.1
- Disclosed:
- Mar 7, 2024
CVE-2024-1419 on NVD →
The Plus Addons for Elementor <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting Header Meta Content Widget
medium
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ attribute of the Header Meta Content widget in all versions up to, and including, 5.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with c...
- CVSS:
- 6.4
- Affected:
- up to 5.4.0
- Fixed in:
- 5.4.1
- Disclosed:
- Mar 6, 2024
CVE-2024-1419 on NVD →
The Plus Addons for Elementor <= 5.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...
- CVSS:
- 6.4
- Affected:
- up to 5.3.3
- Fixed in:
- 5.3.4
- Disclosed:
- Jan 30, 2024
CVE-2024-23511 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 2.0.7
unknown
[en] The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registration form to the Elementor page builders functionality. As part of the registration form, users can choose which role to set as the defau...
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Mar 7, 2023
CVE-2021-4331 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 2.0.7
unknown
[en] The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box. Unfortunately, the plugin used file...
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Mar 7, 2023
CVE-2021-4332 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 2.0.6
unknown
[en] The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- May 5, 2021
CVE-2021-24266 on NVD →
The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege Escalation
high
The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registration form to the Elementor page builders functionality. As part of the registration form, users can choose which role to set as the default fo...
- CVSS:
- 8.8
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.7
- Disclosed:
- Apr 14, 2021
CVE-2021-4331 on NVD →
The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read
medium
The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box. Unfortunately, the plugin used file_get_...
- CVSS:
- 6.5
- Affected:
- up to 2.0.6, 4.0 – 4.1.9
- Fixed in:
- 2.0.7
- Disclosed:
- Apr 14, 2021
CVE-2021-4332 on NVD →
The Plus Addons for Elementor Page Builder Lite < 2.0.6 - Authenticated Stored Cross-Site Scripting
medium
The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
- CVSS:
- 5.4
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Apr 13, 2021
CVE-2021-24266 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 2.0.6
unknown
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress The Plus Addons for Elementor Page Builder Lite plugin (versions <= 2.0.5).
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Apr 13, 2021
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.3.11
unknown
- Affected:
- up to 6.3.11
- Fixed in:
- 6.3.11
CVE-2025-7646 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.3.16
unknown
- Affected:
- up to 6.3.16
- Fixed in:
- 6.3.16
CVE-2025-9698 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.2.3
unknown
- Affected:
- up to 6.2.3
- Fixed in:
- 6.2.3
CVE-2025-1287 on NVD →
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.3.4
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 5.3.4
- Fixed in:
- 5.3.4
CVE-2024-23511 on NVD →