← WordPress Vulnerabilities
WordPress security by component

Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor – Popular Elementor Templates & Widgets is a WordPress component with 29 published CVE records in this archive. The latest tracked vulnerability was published Jul 21, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: essential-addons-for-elementor-lite

CVE-2026-15145: Essential Addons for Elementor – Popular Elementor Templates & Widgets: Cross-site scripting

Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 6.6.11.

PublishedJul 21, 2026
Known safe version> 6.6.11
Safe version
Jul 21, 2026 CVE-2026-15145
Essential Addons for Elementor – Popular Elementor Templates & Widgets: Cross-site scripting
Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 6.6.11.
> 6.6.11
CVE6.4
NVDPending
Jul 21, 2026 CVE-2026-15156
Essential Addons for Elementor – Popular Elementor Templates & Widgets: Cross-site scripting
Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 6.6.11.
> 6.6.11
CVE6.4
NVDPending
Jul 11, 2026 CVE-2026-15155
Essential Addons for Elementor – Popular Elementor Templates & Widgets: Privilege escalation or authentication bypass
Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by privilege escalation or authentication bypass. Exploitation requires at least contributor-level access. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 6.6.10.
> 6.6.10
CVE8.8
NVDPending
Jun 15, 2026 CVE-2026-25440
Essential Addons for Elementor: A security weakness
Essential Addons for Elementor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a to < 6.6.0.
6.6.0
CVE5.3
NVDPending
Jun 06, 2026 CVE-2026-7665
Essential Addons for Elementor – Popular Elementor Templates & Widgets: A security weakness
Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 6.6.4.
> 6.6.4
CVE5.3
NVDPending
Feb 19, 2026 CVE-2026-23543
Essential Addons for Elementor: A security weakness
Essential Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 16, 2026 CVE-2026-1004
Essential Addons for Elementor: Sensitive information exposure
Essential Addons for Elementor is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Dec 17, 2025 CVE-2025-13977
Essential Addons for Elementor – Popular Elementor Templates & Widgets: Cross-site scripting
Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Aug 15, 2025 CVE-2025-8451
Essential Addons for Elementor – Popular Elementor Templates & Widgets: Cross-site scripting
Essential Addons for Elementor – Popular Elementor Templates & Widgets is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Jun 07, 2025 CVE-2024-9994
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 07, 2025 CVE-2024-9993
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Nov 15, 2024 CVE-2024-8979
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders: Sensitive information exposure
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders is affected by sensitive information exposure. Exploitation requires at least author-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE8.0
NVD5.7
Nov 15, 2024 CVE-2024-8978
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders: Sensitive information exposure
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.7
NVDPending
Nov 15, 2024 CVE-2024-8961
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Sep 13, 2024 CVE-2024-8742
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Sep 11, 2024 CVE-2024-8440
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Aug 13, 2024 CVE-2024-7092
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 11, 2024 CVE-2024-5189
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 06, 2024 CVE-2024-5188
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 30, 2024 CVE-2024-5073
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 17, 2024 CVE-2023-41955
Essential Addons for Elementor: Privilege escalation or authentication bypass
Essential Addons for Elementor is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVD8.8
May 14, 2024 CVE-2024-4624
Essential Addons For Elementor Lite: Cross-site scripting
Essential Addons For Elementor Lite is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-4156
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-2623
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Feb 29, 2024 CVE-2024-1276
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Feb 29, 2024 CVE-2024-1236
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Feb 29, 2024 CVE-2024-1172
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Jan 04, 2024 CVE-2023-7044
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 12, 2023 CVE-2023-32243
Essential Addons for Elementor: Privilege escalation or authentication bypass
Essential Addons for Elementor is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD9.8