plugin

Themesflat Addons For Elementor Vulnerabilities

26 known security issues reported for the Themesflat Addons For Elementor WordPress plugin. Most recent disclosed Mar 23, 2026.

1 critical 12 medium

Running Themesflat Addons For Elementor on your site? Check whether your installed version is affected.

Scan your site free

themesflat-addons-for-elementor <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The themesflat-addons-for-elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Mar 23, 2026

CVE-2026-39500 on NVD →

Themesflat Addons For Elementor <= 2.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider widget in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and a...

CVSS:
6.4
Affected:
up to 2.2.5
Fixed in:
2.2.6
Disclosed:
Apr 18, 2025

CVE-2025-3275 on NVD →

Themesflat Addons For Elementor <= 2.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Mar 31, 2025

CVE-2025-31567 on NVD →

Themesflat Addons For Elementor [themesflat-addons-for-elementor] <= 2.2.6 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows Stored XSS. This issue affects Themesflat Addons For Elementor: from n/a through 2.2.5.

Affected:
up to 2.2.6
Fix:
No patched version reported
Disclosed:
Mar 31, 2025

CVE-2025-31567 on NVD →

Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.5

unknown

[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access...

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Jan 8, 2025

CVE-2024-12205 on NVD →

Themesflat Addons For Elementor <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and a...

CVSS:
6.4
Affected:
up to 2.2.4
Fixed in:
2.2.5
Disclosed:
Jan 7, 2025

CVE-2024-12205 on NVD →

Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows DOM-Based XSS.This issue affects Themesflat Addons For Elementor: from n/a through 2.2.2.

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Dec 6, 2024

CVE-2024-53796 on NVD →

Themesflat Addons For Elementor <= 2.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Dec 2, 2024

CVE-2024-53796 on NVD →

Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.2

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows Stored XSS.This issue affects Themesflat Addons For Elementor: from n/a through 2.2.0.

Affected:
up to 2.2.2
Fixed in:
2.2.2
Disclosed:
Oct 17, 2024

CVE-2024-49310 on NVD →

Themesflat Addons For Elementor <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Oct 15, 2024

CVE-2024-49310 on NVD →

Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.2

unknown

[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract limited post information from draft and futur...

Affected:
up to 2.2.2
Fixed in:
2.2.2
Disclosed:
Sep 25, 2024

CVE-2024-8516 on NVD →

Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.2

unknown

[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on URL attributes....

Affected:
up to 2.2.2
Fixed in:
2.2.2
Disclosed:
Sep 25, 2024

CVE-2024-8515 on NVD →

Themesflat Addons For Elementor <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on URL attributes. This...

CVSS:
6.4
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Sep 24, 2024

CVE-2024-8515 on NVD →

Themesflat Addons For Elementor <= 2.2.1 - Authenticated (Contributor+) Information Exposure

medium

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract limited post information from draft and future sch...

CVSS:
4.3
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Sep 24, 2024

CVE-2024-8516 on NVD →

Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3

unknown

[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget tags in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Jun 6, 2024

CVE-2024-2922 on NVD →

Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3

unknown

[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget's titles in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke...

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Jun 6, 2024

CVE-2024-4459 on NVD →

Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3

unknown

[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TF Group Image, TF Nav Menu, TF Posts, TF Woo Product Grid, TF Accordion, and TF Image Box widgets in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output esc...

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Jun 6, 2024

CVE-2024-4212 on NVD →

Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3

unknown

[en] The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets via URL parameters in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor ac...

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Jun 6, 2024

CVE-2024-4458 on NVD →

Themesflat Addons For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Tags

medium

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget tags in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...

CVSS:
6.4
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Jun 5, 2024

CVE-2024-2922 on NVD →

Themesflat Addons For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via URLs

medium

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets via URL parameters in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access...

CVSS:
6.4
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Jun 5, 2024

CVE-2024-4458 on NVD →

Themesflat Addons For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting in Multiple Widgets

medium

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TF Group Image, TF Nav Menu, TF Posts, TF Woo Product Grid, TF Accordion, and TF Image Box widgets in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping...

CVSS:
6.4
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Jun 5, 2024

CVE-2024-4212 on NVD →

Themesflat Addons For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Titles

medium

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget's titles in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...

CVSS:
6.4
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Jun 5, 2024

CVE-2024-4459 on NVD →

Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.1.3

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows Stored XSS.This issue affects Themesflat Addons For Elementor: from n/a through 2.1.2.

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Jun 4, 2024

CVE-2024-35666 on NVD →

Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.0.1

unknown

[en] Deserialization of Untrusted Data vulnerability in Themesflat Themesflat Addons For Elementor.This issue affects Themesflat Addons For Elementor: from n/a through 2.0.0.

Affected:
up to 2.0.1
Fixed in:
2.0.1
Disclosed:
Dec 19, 2023

CVE-2023-37390 on NVD →

Themesflat Addons For Elementor <= 2.0.0 - Unauthenticated PHP Object Injection

critical

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.0 via deserialization of untrusted input through the 'settings' parameter retrieved from the tf_product_filter nopriv AJAX action. This allows unauthenticated attackers to inject a PHP Ob...

CVSS:
9.8
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
Aug 7, 2023

CVE-2023-37390 on NVD →

Themesflat Addons For Elementor [themesflat-addons-for-elementor] < 2.2.6

unknown
Affected:
up to 2.2.6
Fixed in:
2.2.6

CVE-2025-3275 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database