← WordPress Vulnerabilities
WordPress security by component

Qi Addons For Elementor

Qi Addons For Elementor is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Aug 02, 2025; the highest CVE/CNA score is 7.5.

Plugin slug: qi-addons-for-elementor

CVE-2025-8146: Qi Addons For Elementor: Cross-site scripting

Qi Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedAug 02, 2025
Safe version guidanceSee mitigation notes
Safe version
Aug 02, 2025 CVE-2025-8146
Qi Addons For Elementor: Cross-site scripting
Qi Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Jun 28, 2025 CVE-2025-6252
Qi Addons For Elementor: Cross-site scripting
Qi Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 04, 2025 CVE-2024-13699
Qi Addons For Elementor: Cross-site scripting
Qi Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Oct 23, 2024 CVE-2024-9530
Qi Addons For Elementor: Sensitive information exposure
Qi Addons For Elementor is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVDPending
Jun 07, 2024 CVE-2024-4887
Qi Addons For Elementor: Filesystem traversal
Qi Addons For Elementor is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Jun 06, 2024 CVE-2024-4364
Qi Addons For Elementor: Cross-site scripting
Qi Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 17, 2024 CVE-2023-47679
Qi Addons For Elementor: Filesystem traversal
Qi Addons For Elementor is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.4
NVD8.8
Apr 27, 2024 CVE-2024-3309
Qi Addons For Elementor: Cross-site scripting
Qi Addons For Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-0826
Qi Addons For Elementor: Cross-site scripting
Qi Addons For Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Nov 14, 2023 CVE-2023-47680
Qi Addons For Elementor: Cross-site scripting
Qi Addons For Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4