WordPress security by component
Sky Addons for Elementor
Sky Addons for Elementor (sky-elementor-addons) is a WordPress plugin with 7 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 8.1.
Plugin slug:
sky-elementor-addonsLatest vulnerability
CVE-2026-62109: Sky Addons for Elementor exposes editor-level SQL injection
Sky Addons for Elementor through 3.8.4 permits SQL injection by an authenticated Editor. The CNA vector requires no user interaction, rates confidentiality impact as high and availability impact as low, and does not claim database modification. The authoritative export does not identify the endpoint, action, parameter, query-building function, or SQL context.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-62109
Sky Addons for Elementor exposes editor-level SQL injection
Sky Addons for Elementor through 3.8.4 permits SQL injection by an authenticated Editor. The CNA vector requires no user interaction, rates confidentiality impact as high and availability impact as low, and does not claim database modification. The authoritative export does not identify the endpoint, action, parameter, query-building function, or SQL context.
|
3.8.5 |
CVE7.6
NVDPending
|
| May 08, 2026 |
CVE-2026-7475
Sky Addons – Elementor Addons with Widgets & Templates: Cross-site scripting
Sky Addons – Elementor Addons with Widgets & Templates is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.3.2.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jul 29, 2025 |
CVE-2025-8216
Sky Addons for Elementor: Cross-site scripting
Sky Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 24, 2025 |
CVE-2025-46260
Sky Addons for Elementor: Cross-site scripting
Sky Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Nov 22, 2024 |
CVE-2024-11601
Sky Elementor Addons: Cross-site request forgery
Sky Elementor Addons is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Nov 22, 2024 |
CVE-2024-11104
Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs): Denial of service
Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) is affected by denial of service. Exploitation requires an authenticated subscriber account. A successful request can exhaust or disrupt the affected operation and make site functionality unavailable.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Jul 20, 2024 |
CVE-2024-38687
Sky Addons for Elementor: Cross-site scripting
Sky Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|