WordPress security by component
Essential Addons for Elementor – Popular Elementor Templates & Widgets
Plugin description
Essential Addons for Elementor – Popular Elementor Templates & Widgets is a WordPress component with 29 published CVE records in this archive. The latest tracked vulnerability was published Jul 21, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
essential-addons-for-elementor-liteLatest vulnerability
CVE-2026-15145: Essential Addons for Elementor – Popular Elementor Templates & Widgets: Cross-site scripting
Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 6.6.11.
| Safe version |
|
||
|---|---|---|---|
| Jul 21, 2026 |
CVE-2026-15145
Essential Addons for Elementor – Popular Elementor Templates & Widgets: Cross-site scripting
Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 6.6.11.
|
> 6.6.11 |
CVE6.4
NVDPending
|
| Jul 21, 2026 |
CVE-2026-15156
Essential Addons for Elementor – Popular Elementor Templates & Widgets: Cross-site scripting
Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 6.6.11.
|
> 6.6.11 |
CVE6.4
NVDPending
|
| Jul 11, 2026 |
CVE-2026-15155
Essential Addons for Elementor – Popular Elementor Templates & Widgets: Privilege escalation or authentication bypass
Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by privilege escalation or authentication bypass. Exploitation requires at least contributor-level access. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 6.6.10.
|
> 6.6.10 |
CVE8.8
NVDPending
|
| Jun 15, 2026 |
CVE-2026-25440
Essential Addons for Elementor: A security weakness
Essential Addons for Elementor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a to < 6.6.0.
|
6.6.0 |
CVE5.3
NVDPending
|
| Jun 06, 2026 |
CVE-2026-7665
Essential Addons for Elementor – Popular Elementor Templates & Widgets: A security weakness
Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.6.4.
|
> 6.6.4 |
CVE5.3
NVDPending
|
| Feb 19, 2026 |
CVE-2026-23543
Essential Addons for Elementor: A security weakness
Essential Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 16, 2026 |
CVE-2026-1004
Essential Addons for Elementor: Sensitive information exposure
Essential Addons for Elementor is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 17, 2025 |
CVE-2025-13977
Essential Addons for Elementor – Popular Elementor Templates & Widgets: Cross-site scripting
Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Aug 15, 2025 |
CVE-2025-8451
Essential Addons for Elementor – Popular Elementor Templates & Widgets: Cross-site scripting
Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jun 07, 2025 |
CVE-2024-9994
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 07, 2025 |
CVE-2024-9993
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Nov 15, 2024 |
CVE-2024-8979
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders: Sensitive information exposure
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders is affected by sensitive information exposure. Exploitation requires at least author-level access. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE8.0
NVD5.7
|
| Nov 15, 2024 |
CVE-2024-8978
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders: Sensitive information exposure
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.7
NVDPending
|
| Nov 15, 2024 |
CVE-2024-8961
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Sep 13, 2024 |
CVE-2024-8742
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Sep 11, 2024 |
CVE-2024-8440
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Aug 13, 2024 |
CVE-2024-7092
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 11, 2024 |
CVE-2024-5189
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 06, 2024 |
CVE-2024-5188
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 30, 2024 |
CVE-2024-5073
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 17, 2024 |
CVE-2023-41955
Essential Addons for Elementor: Privilege escalation or authentication bypass
Essential Addons for Elementor is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| May 14, 2024 |
CVE-2024-4624
Essential Addons For Elementor Lite: Cross-site scripting
Essential Addons For Elementor Lite is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-4156
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 09, 2024 |
CVE-2024-2623
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 29, 2024 |
CVE-2024-1276
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 29, 2024 |
CVE-2024-1236
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 29, 2024 |
CVE-2024-1172
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jan 04, 2024 |
CVE-2023-7044
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 12, 2023 |
CVE-2023-32243
Essential Addons for Elementor: Privilege escalation or authentication bypass
Essential Addons for Elementor is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVD9.8
|