Essential Addons for Elementor
Essential Addons for Elementor adds widgets, templates, kits, and WooCommerce elements for building WordPress websites.
Essential Addons for Elementor (essential-addons-for-elementor) is a WordPress plugin with 35 published CVE records in this archive. The latest tracked vulnerability was published Jul 30, 2026; the highest published CVSS base score is 9.8.
essential-addons-for-elementorCVE-2026-13345: Essential Addons Product Compare exposes unpublished WooCommerce products
Essential Addons for Elementor - Lite before 6.6.10 exposes unpublished WooCommerce product data through the public eael_product_grid AJAX action when a published Product Grid widget has Compare enabled. An anonymous attacker can scrape the widget's eael_product_grid nonce and page_id and widget_id values from public HTML, then submit an attacker-selected product_ids JSON array to /wp-admin/admin-ajax.php. The compare path passes each ID through static_get_products_list() to wc_get_product() without checking product status, visibility, password protection, or caller authorization, disclosing the title, current price, and SKU of draft, pending, and private products. Version 6.6.10 adds security checks to the Woo Product Compare feature.
| Safe version |
|
||
|---|---|---|---|
| Jul 30, 2026 |
CVE-2026-13345
Essential Addons Product Compare exposes unpublished WooCommerce products
Essential Addons for Elementor - Lite before 6.6.10 exposes unpublished WooCommerce product data through the public eael_product_grid AJAX action when a published Product Grid widget has Compare enabled. An anonymous attacker can scrape the widget's eael_product_grid nonce and page_id and widget_id values from public HTML, then submit an attacker-selected product_ids JSON array to /wp-admin/admin-ajax.php. The compare path passes each ID through static_get_products_list() to wc_get_product() without checking product status, visibility, password protection, or caller authorization, disclosing the title, current price, and SKU of draft, pending, and private products. Version 6.6.10 adds security checks to the Woo Product Compare feature.
|
6.6.10 |
CVE5.3
NVDPending
|
| Jul 30, 2026 |
CVE-2026-13344
Essential Addons Pricing Table title tags permit contributor stored XSS
Essential Addons for Elementor - Lite before 6.6.10 fails to restrict the Pricing Table widget's eael_pricing_table_title_tag setting to valid HTML tag names. A Contributor can use the normal authenticated Elementor action=elementor_ajax save_builder operation on a post they own and place a metacharacter-free value such as an img tag name plus an onerror handler in that setting. The value survives post-save filtering as plain text; esc_html() does not change it, and the renderer later emits it in HTML tag-name position, turning the string into an executable element. The payload runs when an Editor or Administrator previews the pending post and after publication for ordinary visitors. Version 6.6.10 validates the Pricing Table Title Tag setting.
|
6.6.10 |
CVE4.8
NVDPending
|
| Dec 30, 2025 |
CVE-2025-69092
Essential Addons for Elementor: Cross-site scripting
Essential Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 31, 2025 |
CVE-2025-64352
Essential Addons for Elementor: A security weakness
Essential Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE2.7
NVDPending
|
| Jul 08, 2025 |
CVE-2025-6244
Essential Addons for Elementor – Popular Elementor Templates and Widgets: Cross-site scripting
Essential Addons for Elementor – Popular Elementor Templates and Widgets is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 17, 2025 |
CVE-2025-24752
Essential Addons for Elementor: Cross-site scripting
Essential Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Apr 16, 2025 |
CVE-2025-39590
Essential Addons for Elementor: Cross-site scripting
Essential Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 16, 2025 |
CVE-2025-39589
Essential Addons for Elementor: A security weakness
Essential Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 31, 2024 |
CVE-2024-56063
Essential Addons for Elementor: Cross-site scripting
Essential Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Oct 16, 2024 |
CVE-2021-4447
Essential Addons for Elementor: Privilege escalation or authentication bypass
Essential Addons for Elementor is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Oct 16, 2024 |
CVE-2021-4446
Essential Addons for Elementor: A security weakness
Essential Addons for Elementor is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVD4.3
|
| Aug 01, 2024 |
CVE-2024-39649
Essential Addons for Elementor: Cross-site scripting
Essential Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jun 07, 2024 |
CVE-2024-5612
Essential Addons for Elementor Pro: Cross-site scripting
Essential Addons for Elementor Pro is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 29, 2024 |
CVE-2024-5086
Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 14, 2024 |
CVE-2024-4449
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 14, 2024 |
CVE-2024-4448
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD6.1
|
| May 14, 2024 |
CVE-2024-4275
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-4003
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-3728
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 25, 2024 |
CVE-2024-3733
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Sensitive information exposure
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Apr 22, 2024 |
CVE-2024-3645
Essential Addons for Elementor Pro: Cross-site scripting
Essential Addons for Elementor Pro is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 17, 2024 |
CVE-2024-3333
Essential Addons for Elementor: Cross-site scripting
Essential Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 09, 2024 |
CVE-2024-2974
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Sensitive information exposure
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Apr 09, 2024 |
CVE-2024-2650
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Mar 30, 2024 |
CVE-2024-3018
Essential Addons for Elementor: Code execution
Essential Addons for Elementor is affected by code execution. Exploitation requires an authenticated author account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Mar 13, 2024 |
CVE-2024-1537
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Mar 13, 2024 |
CVE-2024-1536
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.4
NVDPending
|
| Feb 29, 2024 |
CVE-2024-1171
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Feb 05, 2024 |
CVE-2024-0954
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 05, 2024 |
CVE-2024-0586
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 05, 2024 |
CVE-2024-0585
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jul 20, 2023 |
CVE-2023-3779
Essential Addons For Elementor: A security weakness
Essential Addons For Elementor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Feb 24, 2022 |
CVE-2022-0683
Essential Addons for Elementor Lite: Cross-site scripting
Essential Addons for Elementor Lite is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Feb 01, 2022 |
CVE-2022-0320
Essential Addons for Elementor: Filesystem traversal
Essential Addons for Elementor is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVEPending
NVD9.8
|
| May 05, 2021 |
CVE-2021-24255
Essential Addons for Elementor Lite: Cross-site scripting
Essential Addons for Elementor Lite is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|