| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-68086 | WordPress Reformer for Elementor plugin <= 1.0.6 - Broken Access Control vulnerability | merkulove | Reformer for Elementor | Medium | 5.4 | 2025-12-16 08:13:06 | Deep Dive |
| CVE-2025-68087 | WordPress Modalier for Elementor plugin <= 1.0.6 - Broken Access Control vulnerability | merkulove | Modalier for Elementor | Medium | 5.4 | 2025-12-16 08:13:06 | Deep Dive |
| CVE-2025-68088 | WordPress Huger for Elementor plugin <= 1.1.5 - Broken Access Control vulnerability | merkulove | Huger for Elementor | Medium | 5.4 | 2025-12-16 08:13:06 | Deep Dive |
| CVE-2025-68085 | WordPress Buttoner for Elementor plugin <= 1.0.6 - Settings Change vulnerability | merkulove | Buttoner for Elementor | Medium | 5.4 | 2025-12-16 08:13:06 | Deep Dive |
| CVE-2025-67951 | WordPress WPZOOM Addons for Elementor plugin <= 1.2.10 - Cross Site Scripting (XSS) vulnerability | WPZOOM | WPZOOM Addons for Elementor | Medium | 6.5 | 2025-12-16 08:12:58 | Deep Dive |
| CVE-2025-66166 | WordPress Lottier for Elementor plugin <= 1.0.9 - Broken Access Control vulnerability | merkulove | Lottier for Elementor | Medium | 5.4 | 2025-12-16 08:12:57 | Deep Dive |
| CVE-2025-66162 | WordPress Spoter for Elementor plugin <= 1.04 - Broken Access Control vulnerability | merkulove | Spoter for Elementor | Medium | 5.4 | 2025-12-16 08:12:56 | Deep Dive |
| CVE-2025-66163 | WordPress Masker for Elementor plugin <= 1.1.4 - Broken Access Control vulnerability | merkulove | Masker for Elementor | Medium | 5.4 | 2025-12-16 08:12:56 | Deep Dive |
| CVE-2025-66147 | WordPress Coder for Elementor plugin <= 1.0.13 - Broken Access Control vulnerability | merkulove | Coder for Elementor | Medium | 5.4 | 2025-12-16 08:12:55 | Deep Dive |
| CVE-2025-66161 | WordPress Grider for Elementor plugin <= 1.0.8 - Broken Access Control vulnerability | merkulove | Grider for Elementor | Medium | 5.4 | 2025-12-16 08:12:55 | Deep Dive |
| CVE-2025-64244 | WordPress Restrict Elementor Widgets, Columns and Sections plugin <= 1.12 - Broken Access Control vulnerability | Codexpert, Inc | Restrict Elementor Widgets, Columns and Sections | Medium | 4.3 | 2025-12-16 08:12:49 | Deep Dive |
| CVE-2025-11363 | Royal Elementor Addons and Templates < 1.7.1037 - Unauthenticated Media File Upload | Unknown | Royal Addons for Elementor | - | - | 2025-12-15 06:00:03 | Deep Dive |
| CVE-2025-12537 | Addon Elements for Elementor <= 1.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | wpvibes | Addon Elements for Elementor (formerly Elementor Addon Elements) | Medium | 6.4 | 2025-12-14 05:21:19 | Deep Dive |
| CVE-2025-8687 | Enter Addons <= 2.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown and Image Comparison Widgets | themelooks | Enter Addons – Ultimate Template Builder for Elementor | Medium | 6.4 | 2025-12-13 08:21:15 | Deep Dive |
| CVE-2025-8199 | MarqueeAddons <= 2.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Marquee Widget | debuggersstudio | Marquee Addons for Elementor – Essential Motion Widgets & Templates | Medium | 6.4 | 2025-12-13 08:21:15 | Deep Dive |
| CVE-2025-8195 | JetWidgets For Elementor <= 1.0.20 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison and Subscribe Widgets | jetmonsters | JetWidgets For Elementor | Medium | 6.4 | 2025-12-13 08:21:14 | Deep Dive |
| CVE-2025-7960 | King Addons for Elementor <= 51.1.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets | kingaddons | King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder | Medium | 6.4 | 2025-12-13 08:21:13 | Deep Dive |
| CVE-2025-8779 | All-in-One Addons for Elementor – WidgetKit <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team and Countdown Widgets | shamsbd71 | All-in-One Addons for Elementor – WidgetKit | Medium | 6.4 | 2025-12-13 07:21:05 | Deep Dive |
| CVE-2025-14278 | HT Slider for Elementor <= 1.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | htplugins | HT Slider For Elementor | Medium | 6.4 | 2025-12-13 03:20:26 | Deep Dive |
| CVE-2025-12965 | Magical Posts Display <= 1.2.54 - Authenticated (Author+) Stored Cross-Site Scripting via Magical Posts Accordion Widget | nalam-1 | Magical Posts Display – Elementor Advanced Posts widgets | Medium | 6.4 | 2025-12-12 11:15:50 | Deep Dive |