Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ElementInvader Addons for Elementor — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in ElementInvader Addons for Elementor, with AI-generated Chinese analysis, references, and POCs.

This page tracks public security vulnerabilities affecting ElementInvader Addons for Elementor, categorized under the Elementor plugin ecosystem. It aggregates data on identified weaknesses, including critical flaws in input validation and insecure direct object references that could allow attackers to execute unauthorized code or access sensitive user data. The collection encompasses vulnerability reports from early 2022 through the present, providing a comprehensive historical view of security issues discovered in this popular WordPress extension. Here, researchers and site administrators can track vendor advisories related to ElementInvader Addons to stay informed about patches and remediation steps. Users may also understand the common weakness classes prevalent in this product, such as cross-site scripting and privilege escalation, by reviewing detailed descriptions and impact assessments. Additionally, individuals can look up a product's vulnerability history to assess risk trends over time and determine the maturity of its security posture. This resource serves as a centralized reference for evaluating the safety of installations using ElementInvader Addons, enabling informed decisions regarding updates and plugin alternatives. By consolidating these details, the page supports proactive security management for WordPress environments relying on Elementor and its associated extensions. The information is derived from public disclosures, ensuring transparency and aiding in the broader understanding of the WordPress plugin security landscape.

Vendor: elementinvader

CVE IDTitleCVSSSeverityPublished
CVE-2026-57376 WordPress ElementInvader Addons for Elementor plugin <= 1.4.3 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2026-07-13
CVE-2026-25007 WordPress ElementInvader Addons for Elementor plugin <= 1.4.2 - SQL Injection vulnerability CWE-89 8.5 High2026-03-25
CVE-2026-25028 WordPress ElementInvader Addons for Elementor plugin <= 1.4.1 - Broken Access Control vulnerability CWE-862 5.4 Medium2026-02-03
CVE-2025-10873 Elementinvader Addons for Elementor < 1.4.1 – Unauthenticated Arbitrary Email Sending 5.3 -2025-11-05
CVE-2025-58205 WordPress ElementInvader Addons for Elementor Plugin <= 1.3.6 - Cross Site Scripting (XSS) Vulnerability CWE-79 6.5 Medium2025-08-27
CVE-2025-48288 WordPress ElementInvader Addons for Elementor plugin <= 1.3.5 - Cross Site Scripting (XSS) Vulnerability CWE-79 6.5 Medium2025-05-19
CVE-2025-24729 WordPress ElementInvader Addons for Elementor plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-01-24
CVE-2025-24618 WordPress ElementInvader Addons for Elementor Plugin <= 1.3.1 - Broken Access Control vulnerability CWE-862 4.3 Medium2025-01-24
CVE-2025-24578 WordPress ElementInvader Addons for Elementor plugin <= 1.3.0 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-01-24
CVE-2025-22786 WordPress ElementInvader Addons for Elementor plugin <= 1.2.6 - Local File Inclusion vulnerability CWE-35 7.5 High2025-01-15
CVE-2024-12059 ElementInvader Addons for Elementor <= 1.3.1 - Missing Authorization to Arbitrary Options Read CWE-639 4.3 Medium2024-12-12
CVE-2024-9889 ElementInvader Addons for Elementor <= 1.2.9 - Authenticated (Contributor+) Information Exposure CWE-200 4.3 Medium2024-10-19
CVE-2024-9888 ElementInvader Addons for Elementor <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 5.4 Medium2024-10-16
CVE-2024-47630 WordPress ElementInvader Addons for Elementor plugin <= 1.2.7 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-10-05
CVE-2024-38705 WordPress ElementInvader Addons for Elementor plugin <= 1.2.4 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-07-20
CVE-2024-2308 ElementInvader Addons for Elementor <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-03-16

All 16 known CVE vulnerabilities affecting ElementInvader Addons for Elementor with full Chinese analysis, references, and POCs where available.