← WordPress Vulnerabilities
WordPress security by component

Exclusive Addons Elementor

Exclusive Addons Elementor is a WordPress component with 28 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: exclusive-addons-for-elementor

CVE-2026-66438: Exclusive Addons Elementor exposes protected data without authentication

Exclusive Addons Elementor through 2.8.0 permits an unauthenticated request to retrieve protected data. The Patchstack CNA record does not disclose the endpoint, action, parameter, function or data fields returned, so the sensitivity and practical scope of the disclosure remain unknown.

PublishedJul 27, 2026
Known safe version2.8.1
Safe version
Jul 27, 2026 CVE-2026-66438
Exclusive Addons Elementor exposes protected data without authentication
Exclusive Addons Elementor through 2.8.0 permits an unauthenticated request to retrieve protected data. The Patchstack CNA record does not disclose the endpoint, action, parameter, function or data fields returned, so the sensitivity and practical scope of the disclosure remain unknown.
2.8.1
CVE5.3
NVDPending
Jul 07, 2026 CVE-2026-11328
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.7.9.8.
> 2.7.9.8
CVE6.4
NVDPending
Jul 05, 2026 CVE-2026-59511
Exclusive Addons Elementor: A security weakness
Exclusive Addons Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.7.9.9.
2.8.0
CVE5.3
NVDPending
Jun 26, 2026 CVE-2026-57620
Exclusive Addons Elementor: Cross-site scripting
Exclusive Addons Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.7.9.8.
2.7.9.9
CVE6.5
NVDPending
Aug 06, 2025 CVE-2025-7498
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 27, 2025 CVE-2025-4783
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 19, 2025 CVE-2025-48244
Exclusive Addons Elementor: Cross-site scripting
Exclusive Addons Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Feb 28, 2025 CVE-2025-1571
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Oct 29, 2024 CVE-2024-10312
Exclusive Addons for Elementor: Sensitive information exposure
Exclusive Addons for Elementor is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVDPending
Oct 17, 2024 CVE-2024-49292
Exclusive Addons Elementor: Cross-site scripting
Exclusive Addons Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 26, 2024 CVE-2024-5332
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 15, 2024 CVE-2024-4618
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 03, 2024 CVE-2024-33914
Exclusive Addons Elementor: A security weakness
Exclusive Addons Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD9.8
May 02, 2024 CVE-2024-3985
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-3489
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-2751
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-2750
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-2503
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 16, 2024 CVE-2024-32557
Exclusive Addons Elementor: Cross-site scripting
Exclusive Addons Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 27, 2024 CVE-2024-30177
Exclusive Addons Elementor: Cross-site scripting
Exclusive Addons Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 26, 2024 CVE-2024-30232
Exclusive Addons Elementor: Cross-site scripting
Exclusive Addons Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 13, 2024 CVE-2024-2028
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1414
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1413
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1234
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 05, 2024 CVE-2024-0823
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Jan 27, 2024 CVE-2024-0824
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 02, 2023 CVE-2022-45067
Exclusive Addons For Elementor: Cross-site request forgery
Exclusive Addons For Elementor is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8