WordPress security by component
Exclusive Addons Elementor
Plugin description
Exclusive Addons Elementor is a WordPress component with 28 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 6.5.
Plugin slug:
exclusive-addons-for-elementorLatest vulnerability
CVE-2026-66438: Exclusive Addons Elementor exposes protected data without authentication
Exclusive Addons Elementor through 2.8.0 permits an unauthenticated request to retrieve protected data. The Patchstack CNA record does not disclose the endpoint, action, parameter, function or data fields returned, so the sensitivity and practical scope of the disclosure remain unknown.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-66438
Exclusive Addons Elementor exposes protected data without authentication
Exclusive Addons Elementor through 2.8.0 permits an unauthenticated request to retrieve protected data. The Patchstack CNA record does not disclose the endpoint, action, parameter, function or data fields returned, so the sensitivity and practical scope of the disclosure remain unknown.
|
2.8.1 |
CVE5.3
NVDPending
|
| Jul 07, 2026 |
CVE-2026-11328
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.7.9.8.
|
> 2.7.9.8 |
CVE6.4
NVDPending
|
| Jul 05, 2026 |
CVE-2026-59511
Exclusive Addons Elementor: A security weakness
Exclusive Addons Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.7.9.9.
|
2.8.0 |
CVE5.3
NVDPending
|
| Jun 26, 2026 |
CVE-2026-57620
Exclusive Addons Elementor: Cross-site scripting
Exclusive Addons Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.7.9.8.
|
2.7.9.9 |
CVE6.5
NVDPending
|
| Aug 06, 2025 |
CVE-2025-7498
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 27, 2025 |
CVE-2025-4783
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 19, 2025 |
CVE-2025-48244
Exclusive Addons Elementor: Cross-site scripting
Exclusive Addons Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Feb 28, 2025 |
CVE-2025-1571
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Oct 29, 2024 |
CVE-2024-10312
Exclusive Addons for Elementor: Sensitive information exposure
Exclusive Addons for Elementor is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 17, 2024 |
CVE-2024-49292
Exclusive Addons Elementor: Cross-site scripting
Exclusive Addons Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jun 26, 2024 |
CVE-2024-5332
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 15, 2024 |
CVE-2024-4618
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 03, 2024 |
CVE-2024-33914
Exclusive Addons Elementor: A security weakness
Exclusive Addons Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD9.8
|
| May 02, 2024 |
CVE-2024-3985
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-3489
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-2751
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-2750
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-2503
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 16, 2024 |
CVE-2024-32557
Exclusive Addons Elementor: Cross-site scripting
Exclusive Addons Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 27, 2024 |
CVE-2024-30177
Exclusive Addons Elementor: Cross-site scripting
Exclusive Addons Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 26, 2024 |
CVE-2024-30232
Exclusive Addons Elementor: Cross-site scripting
Exclusive Addons Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-2028
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1414
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1413
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1234
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 05, 2024 |
CVE-2024-0823
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jan 27, 2024 |
CVE-2024-0824
Exclusive Addons for Elementor: Cross-site scripting
Exclusive Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 02, 2023 |
CVE-2022-45067
Exclusive Addons For Elementor: Cross-site request forgery
Exclusive Addons For Elementor is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|