Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Essential Addons for Elementor — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in Essential Addons for Elementor, with AI-generated Chinese analysis, references, and POCs.

Essential Addons for Elementor is a WordPress plugin developed by Essential Themes that has been identified with multiple weakness types including cross-site scripting and improper access control. This page aggregates and catalogs known security vulnerabilities affecting this specific add-on suite, covering incidents reported from 2020 through 2023. By providing a centralized view of these issues, the resource allows security professionals and site administrators to track vendor advisories as they are issued, gain a deeper understanding of specific weakness classes such as broken authentication or insecure direct object references, and look up the complete vulnerability history of the product to assess long-term risk exposure. The data presented here includes details on exploitability, impact severity, and the timeline of disclosure, helping users make informed decisions about patching and migration. This information is derived from public security databases, vendor security pages, and community reports, ensuring a comprehensive overview of the plugin's security posture over time. Users can utilize this index to identify patterns in vulnerability discovery, compare the frequency of issues across different versions, and evaluate the effectiveness of past remediation efforts. The goal is to provide transparency into the security landscape surrounding Essential Addons for Elementor, enabling proactive defense strategies and reducing the window of exposure to potential attacks. This aggregated view serves as a critical resource for maintaining the integrity and safety of WordPress environments relying on this popular plugin ecosystem.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-13344 Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag --2026-07-30
CVE-2026-13345 Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table --2026-07-30
CVE-2026-25440 WordPress Essential Addons for Elementor plugin < 6.6.0 - Broken Access Control vulnerability CWE-862 5.3 Medium2026-06-15
CVE-2026-23543 WordPress Essential Addons for Elementor plugin <= 6.5.5 - Broken Access Control vulnerability CWE-862 5.3 Medium2026-02-19
CVE-2025-69092 WordPress Essential Addons for Elementor plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-12-30
CVE-2025-64352 WordPress Essential Addons for Elementor plugin <= 6.2.4 - Broken Access Control vulnerability CWE-862 2.7 Low2025-10-31
CVE-2025-24752 WordPress Essential Addons for Elementor plugin <= 6.0.14 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2025-04-17
CVE-2025-39589 WordPress Essential Addons for Elementor plugin <= 6.1.9 - Sensitive Data Exposure Vulnerability CWE-497 4.3 Medium2025-04-16
CVE-2025-39590 WordPress Essential Addons for Elementor plugin <= 6.1.9 - Cross Site Scripting (XSS) Vulnerability CWE-79 6.5 Medium2025-04-16
CVE-2024-56063 WordPress Essential Addons for Elementor plugin <= 6.0.7 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-12-31
CVE-2024-39649 WordPress Essential Addons for Elementor plugin <= 5.9.26 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-08-01
CVE-2023-41955 WordPress Essential Addons for Elementor plugin <= 5.8.8 - Contributor+ Privilege Escalation vulnerability CWE-269 8.8 High2024-05-17
CVE-2023-32243 WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation CWE-287 9.8 Critical2023-05-12
CVE-2022-0320 Essential Addons for Elementor < 5.0.5 - Unauthenticated LFI CWE-22 9.8 -2022-02-01
CVE-2021-24255 Essential Addons for Elementor < 4.5.4 - Contributor+ Stored Cross-Site Scripting (XSS) CWE-79 5.4 -2021-05-05

All 15 known CVE vulnerabilities affecting Essential Addons for Elementor with full Chinese analysis, references, and POCs where available.