| CVE-2024-5647 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library | blossomthemes | BlossomThemes Social Feed | Medium | 6.4 | 2025-07-03 09:22:19 | Deep Dive |
| CVE-2025-5944 | Element Pack Addons for Elementor <= 8.0.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute | bdthemes | Element Pack Elementor Addons and Templates | Medium | 6.4 | 2025-07-03 04:25:01 | Deep Dive |
| CVE-2025-2330 | All-in-One Addons for Elementor – WidgetKit <= 2.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via button+modal Widget | shamsbd71 | All-in-One Addons for Elementor – WidgetKit | Medium | 6.4 | 2025-07-02 09:23:25 | Deep Dive |
| CVE-2025-6686 | Magic Buttons for Elementor <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via magic-button Shortcode | rexdot | Magic Buttons for Elementor | Medium | 6.4 | 2025-07-02 03:47:24 | Deep Dive |
| CVE-2025-6687 | Magic Buttons for Elementor <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via magic-button Shortcode | rexdot | Magic Buttons for Elementor | Medium | 6.4 | 2025-07-02 03:47:23 | Deep Dive |
| CVE-2025-46259 | WordPress The Plus Addons for Elementor - Pro Plugin < 6.3.7 - Broken Access Control vulnerability | POSIMYTH Innovation | The Plus Addons for Elementor Pro | Medium | 5.4 | 2025-07-01 19:10:23 | Deep Dive |
| CVE-2025-6252 | Qi Addons For Elementor <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | qodeinteractive | Qi Addons For Elementor | Medium | 6.4 | 2025-06-28 04:21:33 | Deep Dive |
| CVE-2025-53339 | WordPress Devnex Addons For Elementor plugin <= 1.0.9 - Local File Inclusion Vulnerability | devnex | Devnex Addons For Elementor | High | 7.5 | 2025-06-27 13:21:45 | Deep Dive |
| CVE-2025-53199 | WordPress HT Slider For Elementor plugin <= 1.6.5 - Cross Site Scripting (XSS) Vulnerability | HT Plugins | HT Slider For Elementor | Medium | 6.5 | 2025-06-27 13:20:59 | Deep Dive |
| CVE-2025-6550 | The Pack Elementor addon <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | webangon | The Pack Elementor addon | Medium | 6.4 | 2025-06-27 07:22:22 | Deep Dive |
| CVE-2025-5338 | Royal Elementor Addons <= 1.7.1028 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets | wproyal | Royal Addons for Elementor – Addons and Templates Kit for Elementor | Medium | 6.4 | 2025-06-26 09:22:03 | Deep Dive |
| CVE-2025-3863 | Post Carousel Slider for Elementor <= 1.6.0 - Authenticated (Subscriber+) Missing Authorization via process_wbelps_promo_form Function | plugindevs | Post Carousel Slider for Elementor | Medium | 4.3 | 2025-06-26 02:06:32 | Deep Dive |
| CVE-2025-50038 | WordPress Anant Addons for Elementor plugin <= 1.2.8 - Cross Site Scripting (XSS) vulnerability | anantaddons | Anant Addons for Elementor | Medium | 6.5 | 2025-06-20 15:03:52 | Deep Dive |
| CVE-2025-4479 | ElementsKit Lite <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | Medium | 6.4 | 2025-06-19 03:40:14 | Deep Dive |
| CVE-2025-30562 | WordPress Navigation Tree Elementor plugin <= 1.0.1 - SQL Injection Vulnerability | wpdistillery | Navigation Tree Elementor | - | - | 2025-06-17 15:01:39 | Deep Dive |
| CVE-2025-49444 | WordPress Reformer for Elementor plugin <= 1.0.5 - Arbitrary File Upload Vulnerability | merkulove | Reformer for Elementor | Critical | 10.0 | 2025-06-17 15:01:11 | Deep Dive |
| CVE-2025-5938 | Digital Marketing and Agency Templates Addons for Elementor <= 1.1.1 - Cross-Site Request Forgery to Import | themebon | Digital Marketing and Agency Templates Addons for Elementor | Medium | 5.3 | 2025-06-13 01:47:51 | Deep Dive |
| CVE-2025-4774 | Premium Addons for Elementor <= 4.11.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget | leap13 | Premium Addons for Elementor – Powerful Elementor Templates & Widgets | Medium | 6.4 | 2025-06-10 11:22:52 | Deep Dive |
| CVE-2025-3076 | Elementor Pro <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | https://elementor.com/ | Elementor Website Builder Pro | Medium | 6.4 | 2025-06-10 04:23:10 | Deep Dive |
| CVE-2024-9993 | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget | wpdevteam | Essential Addons for Elementor – Popular Elementor Templates & Widgets | Medium | 6.4 | 2025-06-07 11:17:51 | Deep Dive |