plugin

The Plus Addons For Elementor Page Builder Vulnerabilities

75 known security issues reported for the The Plus Addons For Elementor Page Builder WordPress plugin. Most recent disclosed May 28, 2026.

1 high 40 medium

Running The Plus Addons For Elementor Page Builder on your site? Check whether your installed version is affected.

Scan your site free

The Plus Addons for Elementor <= 6.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' Parameter

medium

The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions up to, and including, 6.4.15 This is due to insufficient output escaping in the render() function, where the carousel_direction value is plac...

CVSS:
6.4
Affected:
up to 6.4.15
Fixed in:
6.4.16
Disclosed:
May 28, 2026

CVE-2026-9243 on NVD →

The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes

medium

The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting via the Button widget's `custom_attributes` setting in versions up to and including 6.4.11. The `render` function in `modules/widgets/tp_button.php` passed the raw `custom_attributes` string thr...

CVSS:
6.4
Affected:
up to 6.4.11
Fixed in:
6.4.12
Disclosed:
May 21, 2026

CVE-2026-15285 on NVD →

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...

CVSS:
6.4
Affected:
up to 6.4.11
Fixed in:
6.4.12
Disclosed:
May 21, 2026

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...

CVSS:
6.4
Affected:
up to 6.4.11
Fixed in:
6.4.12
Disclosed:
May 21, 2026

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite Widget

medium

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to stored cross-site scripting via the `menu_hover_click` parameter of the Navigation Menu Lite widget in all versions up to, and including, 6.4.11 due to insufficient input sanit...

CVSS:
6.4
Affected:
up to 6.4.11
Fixed in:
6.4.12
Disclosed:
May 13, 2026

CVE-2026-5243 on NVD →

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar

medium

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Progress Bar shortcode in all versions up to, and including, 6.4.9 due to insufficient input sanitization and output escaping on us...

CVSS:
6.4
Affected:
up to 6.4.9
Fixed in:
6.4.10
Disclosed:
Apr 7, 2026

CVE-2026-3311 on NVD →

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay

medium

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.4.7. This is due to the plugin decrypting and trusting attacker-controlled email_data in...

CVSS:
5.3
Affected:
up to 6.4.7
Fixed in:
6.4.8
Disclosed:
Feb 21, 2026

CVE-2026-2385 on NVD →

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type'

medium

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 6.4.7. This is due to the tpae_create_page() AJAX handler authorizing users only with current_user_can('edit_posts...

CVSS:
4.3
Affected:
up to 6.4.7
Fixed in:
6.4.8
Disclosed:
Feb 18, 2026

CVE-2026-2386 on NVD →

The Plus Addons for Elementor <= 6.3.15 - Authenticated (Author+) Stored Cross-Site Scripting via SVG

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.3.15 due to insufficient input sanitization and output escaping. This makes it possible for...

CVSS:
6.4
Affected:
up to 6.3.15
Fixed in:
6.3.16
Disclosed:
Sep 22, 2025

CVE-2025-9698 on NVD →

The Plus Addons for Elementor Page Builder Lite <= 6.3.13 - Missing Authorization

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.3.13. This makes it possible for authenticated attackers, with Contribut...

CVSS:
4.3
Affected:
up to 6.3.13
Fixed in:
6.3.14
Disclosed:
Aug 14, 2025

CVE-2025-55712 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.3.14

unknown

[en] Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 6.3.13.

Affected:
up to 6.3.14
Fixed in:
6.3.14
Disclosed:
Aug 14, 2025

CVE-2025-55712 on NVD →

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom script parameter in all versions up to, and including, 6.3.10 even when the user does not have the unfiltered_html capability. This makes...

CVSS:
6.4
Affected:
up to 6.3.10
Fixed in:
6.3.11
Disclosed:
Jul 31, 2025

CVE-2025-7646 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.2.8

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Innovations The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 6.2.7.

Affected:
up to 6.2.8
Fixed in:
6.2.8
Disclosed:
Jun 6, 2025

CVE-2025-49076 on NVD →

The Plus Addons for Elementor Page Builder Lite <= 6.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject...

CVSS:
6.4
Affected:
up to 6.2.7
Fixed in:
6.2.8
Disclosed:
May 30, 2025

CVE-2025-49076 on NVD →

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown, Syntax Highlighter, and Page Scroll widgets in all versions up to, and including, 6.2.2 due to insufficient input sanitization and ou...

CVSS:
6.4
Affected:
up to 6.2.2
Fixed in:
6.2.3
Disclosed:
Mar 7, 2025

CVE-2025-1287 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.2.0

unknown

[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table Widget's searchable_label parameter in all versions up to, and including, 6.1.8 due to insufficient input sanitization and output esc...

Affected:
up to 6.2.0
Fixed in:
6.2.0
Disclosed:
Feb 1, 2025

CVE-2024-11829 on NVD →

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table Widget's searchable_label parameter in all versions up to, and including, 6.1.8 due to insufficient input sanitization and output escaping...

CVSS:
6.4
Affected:
up to 6.1.8
Fixed in:
6.2.0
Disclosed:
Jan 31, 2025

CVE-2024-11829 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.0.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows DOM-Based XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.6.14.

Affected:
up to 6.0.1
Fixed in:
6.0.1
Disclosed:
Dec 6, 2024

CVE-2024-53823 on NVD →

The Plus Addons for Elementor Page Builder Lite <= 5.6.14 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to injec...

CVSS:
6.4
Affected:
up to 5.6.14
Fixed in:
6.0.1
Disclosed:
Dec 2, 2024

CVE-2024-53823 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.0.4

unknown

[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.3 via the render function in modules/widgets/tp_carousel_anything.php, modules/widgets/tp_page_scroll....

Affected:
up to 6.0.4
Fixed in:
6.0.4
Disclosed:
Nov 20, 2024

CVE-2024-10365 on NVD →

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.0.3 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.3 via the render function in modules/widgets/tp_carousel_anything.php, modules/widgets/tp_page_scroll.php,...

CVSS:
4.3
Affected:
up to 6.0.3
Fixed in:
6.0.4
Disclosed:
Nov 19, 2024

CVE-2024-10365 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3

unknown

[en] Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.6.2.

Affected:
up to 5.6.3
Fixed in:
5.6.3
Disclosed:
Nov 1, 2024

CVE-2024-43932 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.12

unknown

[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.11 via the render function in modules/widgets/tp_accordion.php. This makes it possible for authenticat...

Affected:
up to 5.6.12
Fixed in:
5.6.12
Disclosed:
Oct 11, 2024

CVE-2024-8913 on NVD →

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_template

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.11 via the render function in modules/widgets/tp_accordion.php. This makes it possible for authenticated at...

CVSS:
4.3
Affected:
up to 5.6.11
Fixed in:
5.6.12
Disclosed:
Oct 10, 2024

CVE-2024-8913 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.6.2.

Affected:
up to 5.6.3
Fixed in:
5.6.3
Disclosed:
Sep 17, 2024

CVE-2024-43977 on NVD →

The Plus Addons for Elementor Page Builder Lite <= 5.6.2 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbi...

CVSS:
6.4
Affected:
up to 5.6.2
Fixed in:
5.6.3
Disclosed:
Aug 28, 2024

CVE-2024-43977 on NVD →

The Plus Addons for Elementor Page Builder Lite <= 5.6.2 - Missing Authorization

medium

The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in the /includes/plus-options/extension/cmb2-field-ajax-search.php file in versions up to, and including, 5.6.2. This makes it possible for authenticated attackers, wit...

CVSS:
4.3
Affected:
up to 5.6.2
Fixed in:
5.6.3
Disclosed:
Aug 26, 2024

CVE-2024-43932 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3

unknown

[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the carousel_direction parameter of testimonials widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization and...

Affected:
up to 5.6.3
Fixed in:
5.6.3
Disclosed:
Aug 22, 2024

CVE-2024-5583 on NVD →

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonials Widget Settings

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the carousel_direction parameter of testimonials widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization and outpu...

CVSS:
6.4
Affected:
up to 5.6.2
Fixed in:
5.6.3
Disclosed:
Aug 21, 2024

CVE-2024-5583 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3

unknown

[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_date attribute within the plugin's Video widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization an...

Affected:
up to 5.6.3
Fixed in:
5.6.3
Disclosed:
Aug 20, 2024

CVE-2024-5763 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.3

unknown

[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘res_width_value’ parameter within the plugin's tp_page_scroll widget in all versions up to, and including, 5.6.2 due to insufficient input...

Affected:
up to 5.6.3
Fixed in:
5.6.3
Disclosed:
Aug 20, 2024

CVE-2024-6575 on NVD →

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_date attribute within the plugin's Video widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization and out...

CVSS:
6.4
Affected:
up to 5.6.2
Fixed in:
5.6.3
Disclosed:
Aug 19, 2024

CVE-2024-5763 on NVD →

The Plus Addons for Elementor <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via TP Page Scroll Widget

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘res_width_value’ parameter within the plugin's tp_page_scroll widget in all versions up to, and including, 5.6.2 due to insufficient input sani...

CVSS:
6.4
Affected:
up to 5.6.2
Fixed in:
5.6.3
Disclosed:
Aug 19, 2024

CVE-2024-6575 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.2

unknown

[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied...

Affected:
up to 5.6.2
Fixed in:
5.6.2
Disclosed:
Jul 3, 2024

CVE-2024-4482 on NVD →

The Plus Addons for Elementor <= 5.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied 'text...

CVSS:
6.4
Affected:
up to 5.6.1
Fixed in:
5.6.2
Disclosed:
Jul 2, 2024

CVE-2024-4482 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.6.1

unknown

[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘video_color’ parameter in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes...

Affected:
up to 5.6.1
Fixed in:
5.6.1
Disclosed:
Jun 27, 2024

CVE-2024-4983 on NVD →

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.0- Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘video_color’ parameter in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes it po...

CVSS:
6.4
Affected:
up to 5.6.0
Fixed in:
5.6.1
Disclosed:
Jun 26, 2024

CVE-2024-4983 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.5

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.5.4.

Affected:
up to 5.5.5
Fixed in:
5.5.5
Disclosed:
Jun 8, 2024

CVE-2024-35709 on NVD →

The Plus Addons for Elementor Page Builder Lite <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject...

CVSS:
6.4
Affected:
up to 5.5.4
Fixed in:
5.5.5
Disclosed:
Jun 6, 2024

CVE-2024-35709 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.5

unknown

[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Hover Card widget in all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

Affected:
up to 5.5.5
Fixed in:
5.5.5
Disclosed:
May 24, 2024

CVE-2024-2784 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.3

unknown

[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘xai_username’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. This makes it...

Affected:
up to 5.5.3
Fixed in:
5.5.3
Disclosed:
May 24, 2024

CVE-2024-4484 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.5

unknown

[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers...

Affected:
up to 5.5.5
Fixed in:
5.5.5
Disclosed:
May 24, 2024

CVE-2024-3718 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.3

unknown

[en] The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_custom_attributes’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. Th...

Affected:
up to 5.5.3
Fixed in:
5.5.3
Disclosed:
May 24, 2024

CVE-2024-4485 on NVD →

The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pricing Table, & Flip Box

medium

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wit...

CVSS:
6.4
Affected:
up to 5.5.4
Fixed in:
5.5.5
Disclosed:
May 23, 2024

CVE-2024-3718 on NVD →

The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contibutor+) Stored Cross-Site Scripting via Hover Card

medium

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Hover Card widget in all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...

CVSS:
6.4
Affected:
up to 5.5.4
Fixed in:
5.5.5
Disclosed:
May 23, 2024

CVE-2024-2784 on NVD →

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_custom_attributes’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. This ma...

CVSS:
6.4
Affected:
up to 5.5.2
Fixed in:
5.5.3
Disclosed:
May 23, 2024

CVE-2024-4485 on NVD →

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘xai_username’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. This makes it possi...

CVSS:
6.4
Affected:
up to 5.5.1
Fixed in:
5.5.3
Disclosed:
May 23, 2024

CVE-2024-4484 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0

unknown

[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with co...

Affected:
up to 5.5.0
Fixed in:
5.5.0
Disclosed:
May 9, 2024

CVE-2024-2785 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0

unknown

[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access...

Affected:
up to 5.5.0
Fixed in:
5.5.0
Disclosed:
May 9, 2024

CVE-2024-0445 on NVD →

The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or hi...

CVSS:
6.4
Affected:
up to 5.4.2
Fixed in:
5.5.0
Disclosed:
May 6, 2024

CVE-2024-0445 on NVD →

The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate

medium

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contrib...

CVSS:
6.4
Affected:
up to 5.4.2
Fixed in:
5.5.0
Disclosed:
May 6, 2024

CVE-2024-2785 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.4.2.

Affected:
up to 5.5.0
Fixed in:
5.5.0
Disclosed:
May 6, 2024

CVE-2024-34373 on NVD →

The Plus Addons for Elementor Page Builder Lite <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject...

CVSS:
6.4
Affected:
up to 5.4.2
Fixed in:
5.5.0
Disclosed:
May 3, 2024

CVE-2024-34373 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0

unknown

[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher,...

Affected:
up to 5.5.0
Fixed in:
5.5.0
Disclosed:
May 2, 2024

CVE-2024-3199 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.5.0

unknown

[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in the plugin's widgets in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...

Affected:
up to 5.5.0
Fixed in:
5.5.0
Disclosed:
May 2, 2024

CVE-2024-3197 on NVD →

The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

medium

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to i...

CVSS:
6.4
Affected:
up to 5.4.2
Fixed in:
5.5.0
Disclosed:
Apr 25, 2024

CVE-2024-3199 on NVD →

The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes

medium

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in the plugin's widgets in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...

CVSS:
6.4
Affected:
up to 5.4.2
Fixed in:
5.5.0
Disclosed:
Apr 25, 2024

CVE-2024-3197 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.4.2

unknown

[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Team Member Listing widget. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the ser...

Affected:
up to 5.4.2
Fixed in:
5.4.2
Disclosed:
Mar 27, 2024

CVE-2024-2210 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.4.2

unknown

[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Clients widget. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowin...

Affected:
up to 5.4.2
Fixed in:
5.4.2
Disclosed:
Mar 27, 2024

CVE-2024-2203 on NVD →

The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Clients Widget

medium

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Clients widget. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the...

CVSS:
6.4
Affected:
up to 5.4.1
Fixed in:
5.4.2
Disclosed:
Mar 26, 2024

CVE-2024-2203 on NVD →

The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Team Member Listing

medium

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Team Member Listing widget. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server,...

CVSS:
6.4
Affected:
up to 5.4.1
Fixed in:
5.4.2
Disclosed:
Mar 26, 2024

CVE-2024-2210 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.4.1

unknown

[en] The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ attribute of the Header Meta Content widget in all versions up to, and including, 5.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w...

Affected:
up to 5.4.1
Fixed in:
5.4.1
Disclosed:
Mar 7, 2024

CVE-2024-1419 on NVD →

The Plus Addons for Elementor <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting Header Meta Content Widget

medium

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ attribute of the Header Meta Content widget in all versions up to, and including, 5.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with c...

CVSS:
6.4
Affected:
up to 5.4.0
Fixed in:
5.4.1
Disclosed:
Mar 6, 2024

CVE-2024-1419 on NVD →

The Plus Addons for Elementor <= 5.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...

CVSS:
6.4
Affected:
up to 5.3.3
Fixed in:
5.3.4
Disclosed:
Jan 30, 2024

CVE-2024-23511 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 2.0.7

unknown

[en] The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registration form to the Elementor page builders functionality. As part of the registration form, users can choose which role to set as the defau...

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Mar 7, 2023

CVE-2021-4331 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 2.0.7

unknown

[en] The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box. Unfortunately, the plugin used file...

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Mar 7, 2023

CVE-2021-4332 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 2.0.6

unknown

[en] The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
May 5, 2021

CVE-2021-24266 on NVD →

The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege Escalation

high

The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registration form to the Elementor page builders functionality. As part of the registration form, users can choose which role to set as the default fo...

CVSS:
8.8
Affected:
up to 2.0.6
Fixed in:
2.0.7
Disclosed:
Apr 14, 2021

CVE-2021-4331 on NVD →

The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read

medium

The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box. Unfortunately, the plugin used file_get_...

CVSS:
6.5
Affected:
up to 2.0.6, 4.0 – 4.1.9
Fixed in:
2.0.7
Disclosed:
Apr 14, 2021

CVE-2021-4332 on NVD →

The Plus Addons for Elementor Page Builder Lite < 2.0.6 - Authenticated Stored Cross-Site Scripting

medium

The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVSS:
5.4
Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Apr 13, 2021

CVE-2021-24266 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 2.0.6

unknown

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress The Plus Addons for Elementor Page Builder Lite plugin (versions <= 2.0.5).

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Apr 13, 2021

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.3.11

unknown
Affected:
up to 6.3.11
Fixed in:
6.3.11

CVE-2025-7646 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.3.16

unknown
Affected:
up to 6.3.16
Fixed in:
6.3.16

CVE-2025-9698 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.2.3

unknown
Affected:
up to 6.2.3
Fixed in:
6.2.3

CVE-2025-1287 on NVD →

The Plus Addons for Elementor &#8211; Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 5.3.4

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 5.3.4
Fixed in:
5.3.4

CVE-2024-23511 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database