| CVE-2024-2047 | ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Local File Inclusion in render_raw | roxnor | ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | High | 8.8 | 2024-03-30 04:31:08 | Deep Dive |
| CVE-2024-30496 | WordPress Element Pack Lite plugin <= 5.5.3 - SQL Injection vulnerability | BdThemes | Element Pack Elementor Addons | High | 8.5 | 2024-03-29 13:57:46 | Deep Dive |
| CVE-2024-30423 | WordPress Better Elementor Addons plugin <= 1.3.7 - Cross Site Scripting (XSS) vulnerability | BetterAddons | Better Elementor Addons | Medium | 6.5 | 2024-03-29 13:11:07 | Deep Dive |
| CVE-2024-2250 | 130+ Widgets | Best Addons For Elementor – FREE <= 1.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | xpro | Xpro Addons — 140+ Widgets for Elementor | Medium | 6.4 | 2024-03-29 07:31:02 | Deep Dive |
| CVE-2024-2280 | Better Elementor Addons <= 1.4.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via widget links | wpdive | Better Addons for Elementor | Medium | 6.4 | 2024-03-29 06:44:04 | Deep Dive |
| CVE-2024-30422 | WordPress Elementor Addon Elements plugin <= 1.13.1 - Cross Site Scripting (XSS) vulnerability | WPVibes | Elementor Addon Elements | Medium | 6.5 | 2024-03-28 09:03:36 | Deep Dive |
| CVE-2023-34370 | Server Side Request Forgery (SSRF) vulnerability in Starter Templates plugins | Brainstorm Force | Starter Templates — Elementor, WordPress & Beaver Builder Templates | High | 7.1 | 2024-03-28 06:07:32 | Deep Dive |
| CVE-2024-2091 | Elementor Addon Elements <= 1.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | wpvibes | Addon Elements for Elementor (formerly Elementor Addon Elements) | Medium | 5.4 | 2024-03-28 02:37:11 | Deep Dive |
| CVE-2024-29792 | WordPress Unlimited Elements for Elementor plugin <= 1.5.93 - Reflected Cross Site Scripting (XSS) vulnerability | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | High | 7.1 | 2024-03-27 12:51:32 | Deep Dive |
| CVE-2024-30186 | WordPress Prime Slider plugin <= 3.13.1 - Cross Site Scripting (XSS) vulnerability | BdThemes | Prime Slider – Addons For Elementor | Medium | 6.5 | 2024-03-27 11:51:24 | Deep Dive |
| CVE-2024-30185 | WordPress Element Pack Elementor Addons plugin <= 5.5.3 - Cross Site Scripting (XSS) vulnerability | BdThemes | Element Pack Elementor Addons | Medium | 6.5 | 2024-03-27 11:50:08 | Deep Dive |
| CVE-2024-30177 | WordPress Exclusive Addons for Elementor plugin <= 2.6.8 - Cross Site Scripting (XSS) vulnerability | Exclusive Addons | Exclusive Addons Elementor | Medium | 6.5 | 2024-03-27 10:21:52 | Deep Dive |
| CVE-2024-29936 | WordPress Image Hover Effects – Elementor Addon plugin <= 1.4 - Cross Site Scripting (XSS) vulnerability | Blocksera | Image Hover Effects – Elementor Addon | Medium | 6.5 | 2024-03-27 10:19:48 | Deep Dive |
| CVE-2024-29935 | WordPress Sina Extension for Elementor plugin <= 3.5.0 - Cross Site Scripting (XSS) vulnerability | SinaExtra | Sina Extension for Elementor | Medium | 6.5 | 2024-03-27 10:18:30 | Deep Dive |
| CVE-2024-29934 | WordPress Piotnet Addons For Elementor plugin <= 2.4.25 - Cross Site Scripting (XSS) vulnerability | Piotnet | Piotnet Addons For Elementor | Medium | 6.5 | 2024-03-27 10:16:50 | Deep Dive |
| CVE-2024-29920 | WordPress Move Addons for Elementor plugin <= 1.2.9 - Cross Site Scripting (XSS) vulnerability | Moveaddons | Move Addons for Elementor | Medium | 6.5 | 2024-03-27 07:13:06 | Deep Dive |
| CVE-2024-29913 | WordPress Tutor LMS Elementor Addons plugin <= 2.1.3 - Cross Site Scripting (XSS) vulnerability | Themeum | Tutor LMS Elementor Addons | Medium | 6.5 | 2024-03-27 07:02:45 | Deep Dive |
| CVE-2024-29911 | WordPress Master Addons for Elementor plugin <= 2.0.5.4.1 - Cross Site Scripting (XSS) vulnerability | Jewel Theme | Master Addons for Elementor | Medium | 6.5 | 2024-03-27 06:59:55 | Deep Dive |
| CVE-2024-1521 | Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Widget SVGZ File Upload | https://elementor.com/ | Elementor Website Builder Pro | Medium | 6.4 | 2024-03-27 06:40:51 | Deep Dive |
| CVE-2024-2120 | Elementor Website Builder Pro <= 3.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation | https://elementor.com/ | Elementor Website Builder Pro | Medium | 5.4 | 2024-03-27 06:40:50 | Deep Dive |