← WordPress Vulnerabilities
WordPress security by component

Elementor Addon Elements

Elementor Addon Elements is a WordPress component with 22 published CVE records in this archive. The latest tracked vulnerability was published Feb 26, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: addon-elements-for-elementor-page-builder

CVE-2026-28131: Elementor Addon Elements: A security weakness

Elementor Addon Elements is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedFeb 26, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 26, 2026 CVE-2026-28131
Elementor Addon Elements: A security weakness
Elementor Addon Elements is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Jan 15, 2025 CVE-2024-13215
Elementor Addon Elements: Sensitive information exposure
Elementor Addon Elements is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVDPending
Aug 30, 2024 CVE-2024-7122
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Aug 30, 2024 CVE-2024-4401
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 27, 2024 CVE-2024-4570
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 27, 2024 CVE-2024-4569
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 12, 2024 CVE-2024-2092
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
May 02, 2024 CVE-2024-3743
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-2792
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 28, 2024 CVE-2024-30422
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 28, 2024 CVE-2024-2091
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD4.6
Mar 19, 2024 CVE-2024-29107
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 13, 2024 CVE-2024-1422
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1393
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1392
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1391
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1358
Elementor Addon Elements: Filesystem traversal
Elementor Addon Elements is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVD6.5
Feb 05, 2024 CVE-2024-0834
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Nov 15, 2023 CVE-2023-5381
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Nov 15, 2023 CVE-2023-4723
Elementor Addon Elements: Sensitive information exposure
Elementor Addon Elements is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVD5.3
Nov 15, 2023 CVE-2023-4690
Elementor Addon Elements: Cross-site request forgery
Elementor Addon Elements is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Nov 15, 2023 CVE-2023-4689
Elementor Addon Elements: Cross-site request forgery
Elementor Addon Elements is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3