Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Essential Addons for Elementor – Popular Elementor Templates & Widgets — Vulnerabilities & Security Advisories 43

All 43 CVE vulnerabilities found in Essential Addons for Elementor – Popular Elementor Templates & Widgets, with AI-generated Chinese analysis, references, and POCs.

This page catalogs public security vulnerabilities, weaknesses, and advisory data associated with the Essential Addons for Elementor plugin, a popular Elementor Templates and Widgets extension. It aggregates findings from various disclosure channels and databases to provide a comprehensive view of the security landscape surrounding this widely used WordPress extension. The collection covers vulnerability reports identified over the last several years, capturing a broad spectrum of issues ranging from critical remote code execution flaws to lower-severity cross-site scripting incidents. Visitors to this resource can efficiently track the vendor’s historical security advisories to understand their response times and patching practices. Users can also delve into specific weakness classes, such as insecure deserialization or authorization bypasses, to comprehend the technical nature of the threats facing the plugin. Additionally, the page allows for a detailed lookup of the product’s vulnerability history, offering insights into recurring problem areas and the evolution of security flaws over time. This structured approach helps developers, site administrators, and security researchers assess the current risk posture of the Essential Addons for Elementor integration. By centralizing this information, the page serves as a vital reference for maintaining the integrity and safety of WordPress sites that rely on this specific addon suite. It does not provide remediation steps directly but offers the necessary data to inform decision-making regarding updates, mitigation strategies, and alternative solutions in the event of unresolved critical issues.

Vendor: wpdevteam

CVE IDTitleCVSSSeverityPublished
CVE-2024-2650 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-20 6.4 Medium2024-04-09
CVE-2024-3018 Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpassword CWE-502 8.8 High2024-03-30
CVE-2024-1537 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table CWE-79 6.4 Medium2024-03-13
CVE-2024-1536 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar CWE-79 7.4 High2024-03-13
CVE-2024-1171 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery CWE-79 5.4 Medium2024-02-20
CVE-2024-1172 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion CWE-79 5.4 Medium2024-02-20
CVE-2024-1276 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-20
CVE-2024-1236 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-20
CVE-2024-0586 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scritping CWE-79 6.4 Medium2024-02-05
CVE-2024-0954 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-05
CVE-2024-0585 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl CWE-79 5.4 Medium2024-02-05
CVE-2023-7044 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-01-04
CVE-2023-3779 Essential Addons For Elementor <=5.8.1 - Unauthenticated MailChimp API Key Disclosure CWE-200 5.3 Medium2023-07-20

All 43 known CVE vulnerabilities affecting Essential Addons for Elementor – Popular Elementor Templates & Widgets with full Chinese analysis, references, and POCs where available.