← WordPress Vulnerabilities
WordPress security by component

Essential Addons for Elementor

Essential Addons for Elementor adds widgets, templates, kits, and WooCommerce elements for building WordPress websites.

Essential Addons for Elementor (essential-addons-for-elementor) is a WordPress plugin with 35 published CVE records in this archive. The latest tracked vulnerability was published Jul 30, 2026; the highest published CVSS base score is 9.8.

Plugin slug: essential-addons-for-elementor

CVE-2026-13345: Essential Addons Product Compare exposes unpublished WooCommerce products

Essential Addons for Elementor - Lite before 6.6.10 exposes unpublished WooCommerce product data through the public eael_product_grid AJAX action when a published Product Grid widget has Compare enabled. An anonymous attacker can scrape the widget's eael_product_grid nonce and page_id and widget_id values from public HTML, then submit an attacker-selected product_ids JSON array to /wp-admin/admin-ajax.php. The compare path passes each ID through static_get_products_list() to wc_get_product() without checking product status, visibility, password protection, or caller authorization, disclosing the title, current price, and SKU of draft, pending, and private products. Version 6.6.10 adds security checks to the Woo Product Compare feature.

PublishedJul 30, 2026
Known safe version6.6.10
Published vulnerabilities for essential-addons-for-elementor
Safe version
Jul 30, 2026 CVE-2026-13345
Essential Addons Product Compare exposes unpublished WooCommerce products
Essential Addons for Elementor - Lite before 6.6.10 exposes unpublished WooCommerce product data through the public eael_product_grid AJAX action when a published Product Grid widget has Compare enabled. An anonymous attacker can scrape the widget's eael_product_grid nonce and page_id and widget_id values from public HTML, then submit an attacker-selected product_ids JSON array to /wp-admin/admin-ajax.php. The compare path passes each ID through static_get_products_list() to wc_get_product() without checking product status, visibility, password protection, or caller authorization, disclosing the title, current price, and SKU of draft, pending, and private products. Version 6.6.10 adds security checks to the Woo Product Compare feature.
6.6.10
CVE5.3
NVDPending
Jul 30, 2026 CVE-2026-13344
Essential Addons Pricing Table title tags permit contributor stored XSS
Essential Addons for Elementor - Lite before 6.6.10 fails to restrict the Pricing Table widget's eael_pricing_table_title_tag setting to valid HTML tag names. A Contributor can use the normal authenticated Elementor action=elementor_ajax save_builder operation on a post they own and place a metacharacter-free value such as an img tag name plus an onerror handler in that setting. The value survives post-save filtering as plain text; esc_html() does not change it, and the renderer later emits it in HTML tag-name position, turning the string into an executable element. The payload runs when an Editor or Administrator previews the pending post and after publication for ordinary visitors. Version 6.6.10 validates the Pricing Table Title Tag setting.
6.6.10
CVE4.8
NVDPending
Dec 30, 2025 CVE-2025-69092
Essential Addons for Elementor: Cross-site scripting
Essential Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Oct 31, 2025 CVE-2025-64352
Essential Addons for Elementor: A security weakness
Essential Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE2.7
NVDPending
Jul 08, 2025 CVE-2025-6244
Essential Addons for Elementor – Popular Elementor Templates and Widgets: Cross-site scripting
Essential Addons for Elementor – Popular Elementor Templates and Widgets is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 17, 2025 CVE-2025-24752
Essential Addons for Elementor: Cross-site scripting
Essential Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Apr 16, 2025 CVE-2025-39590
Essential Addons for Elementor: Cross-site scripting
Essential Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Apr 16, 2025 CVE-2025-39589
Essential Addons for Elementor: A security weakness
Essential Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Dec 31, 2024 CVE-2024-56063
Essential Addons for Elementor: Cross-site scripting
Essential Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Oct 16, 2024 CVE-2021-4447
Essential Addons for Elementor: Privilege escalation or authentication bypass
Essential Addons for Elementor is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Oct 16, 2024 CVE-2021-4446
Essential Addons for Elementor: A security weakness
Essential Addons for Elementor is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.3
NVD4.3
Aug 01, 2024 CVE-2024-39649
Essential Addons for Elementor: Cross-site scripting
Essential Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 07, 2024 CVE-2024-5612
Essential Addons for Elementor Pro: Cross-site scripting
Essential Addons for Elementor Pro is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 29, 2024 CVE-2024-5086
Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 14, 2024 CVE-2024-4449
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 14, 2024 CVE-2024-4448
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD6.1
May 14, 2024 CVE-2024-4275
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-4003
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-3728
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Apr 25, 2024 CVE-2024-3733
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Sensitive information exposure
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Apr 22, 2024 CVE-2024-3645
Essential Addons for Elementor Pro: Cross-site scripting
Essential Addons for Elementor Pro is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Apr 17, 2024 CVE-2024-3333
Essential Addons for Elementor: Cross-site scripting
Essential Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Apr 09, 2024 CVE-2024-2974
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Sensitive information exposure
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Apr 09, 2024 CVE-2024-2650
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Mar 30, 2024 CVE-2024-3018
Essential Addons for Elementor: Code execution
Essential Addons for Elementor is affected by code execution. Exploitation requires an authenticated author account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Mar 13, 2024 CVE-2024-1537
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Mar 13, 2024 CVE-2024-1536
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.4
NVDPending
Feb 29, 2024 CVE-2024-1171
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Feb 05, 2024 CVE-2024-0954
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 05, 2024 CVE-2024-0586
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 05, 2024 CVE-2024-0585
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders: Cross-site scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Jul 20, 2023 CVE-2023-3779
Essential Addons For Elementor: A security weakness
Essential Addons For Elementor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Feb 24, 2022 CVE-2022-0683
Essential Addons for Elementor Lite: Cross-site scripting
Essential Addons for Elementor Lite is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Feb 01, 2022 CVE-2022-0320
Essential Addons for Elementor: Filesystem traversal
Essential Addons for Elementor is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVEPending
NVD9.8
May 05, 2021 CVE-2021-24255
Essential Addons for Elementor Lite: Cross-site scripting
Essential Addons for Elementor Lite is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4