WordPress security by component
Elementor Addon Elements
Plugin description
Elementor Addon Elements is a WordPress component with 22 published CVE records in this archive. The latest tracked vulnerability was published Feb 26, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
addon-elements-for-elementor-page-builderLatest vulnerability
CVE-2026-28131: Elementor Addon Elements: A security weakness
Elementor Addon Elements is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
| Safe version |
|
||
|---|---|---|---|
| Feb 26, 2026 |
CVE-2026-28131
Elementor Addon Elements: A security weakness
Elementor Addon Elements is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jan 15, 2025 |
CVE-2024-13215
Elementor Addon Elements: Sensitive information exposure
Elementor Addon Elements is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Aug 30, 2024 |
CVE-2024-7122
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Aug 30, 2024 |
CVE-2024-4401
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 27, 2024 |
CVE-2024-4570
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 27, 2024 |
CVE-2024-4569
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 12, 2024 |
CVE-2024-2092
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-3743
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 09, 2024 |
CVE-2024-2792
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 28, 2024 |
CVE-2024-30422
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 28, 2024 |
CVE-2024-2091
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD4.6
|
| Mar 19, 2024 |
CVE-2024-29107
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1422
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1393
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1392
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1391
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1358
Elementor Addon Elements: Filesystem traversal
Elementor Addon Elements is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.8
NVD6.5
|
| Feb 05, 2024 |
CVE-2024-0834
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Nov 15, 2023 |
CVE-2023-5381
Elementor Addon Elements: Cross-site scripting
Elementor Addon Elements is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVD4.8
|
| Nov 15, 2023 |
CVE-2023-4723
Elementor Addon Elements: Sensitive information exposure
Elementor Addon Elements is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Nov 15, 2023 |
CVE-2023-4690
Elementor Addon Elements: Cross-site request forgery
Elementor Addon Elements is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD4.3
|
| Nov 15, 2023 |
CVE-2023-4689
Elementor Addon Elements: Cross-site request forgery
Elementor Addon Elements is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD4.3
|