WordPress security by component
Piotnet Addons For Elementor
Plugin description
Piotnet Addons For Elementor is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Apr 18, 2025; the highest CVE/CNA score is 6.5.
Plugin slug:
piotnet-addons-for-elementorLatest vulnerability
CVE-2024-13650: Piotnet Addons For Elementor: Cross-site scripting
Piotnet Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
| Safe version |
|
||
|---|---|---|---|
| Apr 18, 2025 |
CVE-2024-13650
Piotnet Addons For Elementor: Cross-site scripting
Piotnet Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 04, 2025 |
CVE-2025-32197
Piotnet Addons For Elementor: Cross-site scripting
Piotnet Addons For Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jan 15, 2025 |
CVE-2024-10775
Piotnet Addons For Elementor: A security weakness
Piotnet Addons For Elementor is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jan 07, 2025 |
CVE-2025-22333
Piotnet Addons For Elementor: Cross-site scripting
Piotnet Addons For Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 23, 2024 |
CVE-2024-5502
Piotnet Addons For Elementor: Cross-site scripting
Piotnet Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jul 27, 2024 |
CVE-2024-5614
Piotnet Addons For Elementor: Sensitive information exposure
Piotnet Addons For Elementor is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVDPending
|
| May 22, 2024 |
CVE-2024-4262
Piotnet Addons For Elementor: Cross-site scripting
Piotnet Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| May 18, 2024 |
CVE-2024-4432
Piotnet Addons For Elementor: Cross-site scripting
Piotnet Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 29, 2024 |
CVE-2024-33630
Piotnet Addons For Elementor: Cross-site scripting
Piotnet Addons For Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Mar 27, 2024 |
CVE-2024-29934
Piotnet Addons For Elementor: Cross-site scripting
Piotnet Addons For Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|