← WordPress Vulnerabilities
WordPress security by component

Premium Addons for Elementor – Powerful Elementor Templates & Widgets

Premium Addons for Elementor – Powerful Elementor Templates & Widgets is a WordPress component with 37 published CVE records in this archive. The latest tracked vulnerability was published Jul 11, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: premium-addons-for-elementor

CVE-2026-12141: Premium Addons for Elementor – Powerful Elementor Templates & Widgets: Cross-site scripting

Premium Addons for Elementor – Powerful Elementor Templates & Widgets is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 4.11.84.

PublishedJul 11, 2026
Known safe version> 4.11.84
Safe version
Jul 11, 2026 CVE-2026-12141
Premium Addons for Elementor – Powerful Elementor Templates & Widgets: Cross-site scripting
Premium Addons for Elementor – Powerful Elementor Templates & Widgets is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 4.11.84.
> 4.11.84
CVE4.9
NVDPending
Jan 22, 2026 CVE-2025-69300
Premium Addons for Elementor: A security weakness
Premium Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Dec 24, 2025 CVE-2025-68494
Premium Addons for Elementor: A security weakness
Premium Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 23, 2025 CVE-2025-14163
Premium Addons for Elementor: Cross-site request forgery
Premium Addons for Elementor is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Dec 23, 2025 CVE-2025-14155
Premium Addons for Elementor – Powerful Elementor Templates & Widgets: A security weakness
Premium Addons for Elementor – Powerful Elementor Templates & Widgets is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jul 04, 2025 CVE-2024-11937
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 10, 2025 CVE-2025-4774
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 31, 2024 CVE-2024-56225
Premium Addons for Elementor: A security weakness
Premium Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD8.8
Oct 29, 2024 CVE-2024-10266
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Oct 16, 2024 CVE-2021-4445
Premium Addons for Elementor: A security weakness
Premium Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD4.3
Sep 27, 2024 CVE-2024-8681
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Aug 08, 2024 CVE-2024-6824
Premium Addons for Elementor: A security weakness
Premium Addons for Elementor is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jul 20, 2024 CVE-2024-37922
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jul 12, 2024 CVE-2024-6495
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jul 04, 2024 CVE-2024-6434
Premium Addons for Elementor: A security weakness
Premium Addons for Elementor is affected by a security weakness. Exploitation requires at least author-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE3.1
NVD4.3
Jul 03, 2024 CVE-2024-6340
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 12, 2024 CVE-2024-5553
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD5.4
May 31, 2024 CVE-2024-4379
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
May 31, 2024 CVE-2024-4376
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 31, 2024 CVE-2024-4205
Premium Addons for Elementor: A security weakness
Premium Addons for Elementor is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
May 23, 2024 CVE-2024-4378
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-4203
Premium Addons Pro for Elementor: Cross-site scripting
Premium Addons Pro for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
May 02, 2024 CVE-2024-3885
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-3647
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Apr 24, 2024 CVE-2024-32791
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Apr 10, 2024 CVE-2024-31278
Premium Addons for Elementor: A security weakness
Premium Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD6.5
Apr 10, 2024 CVE-2024-2666
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Apr 10, 2024 CVE-2024-2665
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Apr 10, 2024 CVE-2024-2664
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Apr 09, 2024 CVE-2024-0376
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 19, 2024 CVE-2024-29106
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 15, 2024 CVE-2024-2399
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1680
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-0326
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Feb 29, 2024 CVE-2024-1242
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Feb 10, 2024 CVE-2024-24831
Premium Addons for Elementor: Cross-site scripting
Premium Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
May 05, 2021 CVE-2021-24257
“Premium Addons for Elementor”: Cross-site scripting
“Premium Addons for Elementor” is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4