Browse all 4 CVE security advisories affecting Exclusive Addons. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Exclusive Addons is a WordPress plugin providing premium extensions for Elementor, enabling users to enhance website design with custom widgets and templates. Historically, the plugin has been vulnerable to multiple security issues, including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation vulnerabilities. These weaknesses often stem from insufficient input validation and improper access controls. The plugin has accumulated four CVEs to date, with some vulnerabilities allowing unauthenticated attackers to execute arbitrary code or compromise sensitive data. Security researchers have noted that the plugin's frequent updates sometimes introduce new flaws while attempting to patch existing ones, making it a persistent target for exploitation.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-33914 | WordPress Exclusive Addons for Elementor plugin <= 2.6.9.1 - Broken Access Control on Post Duplication vulnerability — Exclusive Addons ElementorCWE-862 | 4.3 | Medium | 2024-05-03 |
| CVE-2024-32557 | WordPress Exclusive Addons for Elementor plugin <= 2.6.9.2 - Cross Site Scripting (XSS) vulnerability — Exclusive Addons ElementorCWE-79 | 6.5 | Medium | 2024-04-16 |
| CVE-2024-30177 | WordPress Exclusive Addons for Elementor plugin <= 2.6.8 - Cross Site Scripting (XSS) vulnerability — Exclusive Addons ElementorCWE-79 | 6.5 | Medium | 2024-03-27 |
| CVE-2024-30232 | WordPress Exclusive Addons for Elementor plugin <= 2.6.9 - Cross Site Scripting (XSS) vulnerability — Exclusive Addons ElementorCWE-79 | 6.5 | Medium | 2024-03-26 |
This page lists every published CVE security advisory associated with Exclusive Addons. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.