← WordPress Vulnerabilities
WordPress security by component

Magical Addons For Elementor

Magical Addons For Elementor is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Mar 13, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: magical-addons-for-elementor

CVE-2026-32429: Magical Addons For Elementor: Cross-site scripting

Magical Addons For Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedMar 13, 2026
Safe version guidanceSee mitigation notes
Safe version
Mar 13, 2026 CVE-2026-32429
Magical Addons For Elementor: Cross-site scripting
Magical Addons For Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jul 29, 2025 CVE-2025-8196
Magical Addons For Elementor: Cross-site scripting
Magical Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Dec 06, 2024 CVE-2024-54212
Magical Addons For Elementor: Cross-site scripting
Magical Addons For Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Nov 09, 2024 CVE-2024-10352
Magical Addons For Elementor: Sensitive information exposure
Magical Addons For Elementor is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVDPending
Nov 04, 2024 CVE-2024-51665
Magical Addons For Elementor: Server-side request forgery
Magical Addons For Elementor is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.9
NVD4.3
Jul 22, 2024 CVE-2024-38730
Magical Addons For Elementor: Server-side request forgery
Magical Addons For Elementor is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.9
NVD6.4
Jul 20, 2024 CVE-2024-38681
Magical Addons For Elementor: Cross-site scripting
Magical Addons For Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 06, 2024 CVE-2024-5161
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ): Cross-site scripting
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 14, 2024 CVE-2024-2923
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ): Cross-site scripting
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 08, 2024 CVE-2024-34547
Magical Addons For Elementor: Cross-site scripting
Magical Addons For Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4