Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Essential Addons for Elementor — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Essential Addons for Elementor, with AI-generated Chinese analysis, references, and POCs.

This page catalogs security weaknesses associated with Essential Addons for Elementor, a popular WordPress page builder plugin developed by Essential Plugins. The database aggregates known vulnerabilities including cross-site scripting, unauthorized access, and insecure direct object references, covering reports from 2018 through 2023. Here you can track the vendor’s public advisories, understand the specific weakness classes affecting this software, and examine the complete vulnerability history of the product to assess risk over time. The collection focuses on verified security issues that have been disclosed by researchers or the vendor, providing a centralized view of the plugin’s security posture. By organizing these findings chronologically and by severity, the page allows developers and site administrators to quickly identify past flaws and understand how they were mitigated. This information is critical for maintaining the integrity of WordPress sites that rely on Essential Addons for Elementor, as it highlights patterns in code quality and response times. Users can filter entries by vulnerability type or release version to isolate specific concerns relevant to their installation. The data serves as a reference for understanding the historical context of security incidents, helping stakeholders make informed decisions about updates and plugin necessity. No marketing language or promotional content is included; the focus remains strictly on factual vulnerability data and its implications for system security and maintenance protocols.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-18039 Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment --2026-08-14
CVE-2026-13344 Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag --2026-07-30
CVE-2026-13345 Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table --2026-07-30
CVE-2026-25440 WordPress Essential Addons for Elementor plugin < 6.6.0 - Broken Access Control vulnerability CWE-862 5.3 Medium2026-06-15
CVE-2026-23543 WordPress Essential Addons for Elementor plugin <= 6.5.5 - Broken Access Control vulnerability CWE-862 5.3 Medium2026-02-19
CVE-2025-69092 WordPress Essential Addons for Elementor plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-12-30
CVE-2025-64352 WordPress Essential Addons for Elementor plugin <= 6.2.4 - Broken Access Control vulnerability CWE-862 2.7 Low2025-10-31
CVE-2025-24752 WordPress Essential Addons for Elementor plugin <= 6.0.14 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2025-04-17
CVE-2025-39589 WordPress Essential Addons for Elementor plugin <= 6.1.9 - Sensitive Data Exposure Vulnerability CWE-497 4.3 Medium2025-04-16
CVE-2025-39590 WordPress Essential Addons for Elementor plugin <= 6.1.9 - Cross Site Scripting (XSS) Vulnerability CWE-79 6.5 Medium2025-04-16
CVE-2024-56063 WordPress Essential Addons for Elementor plugin <= 6.0.7 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-12-31
CVE-2024-39649 WordPress Essential Addons for Elementor plugin <= 5.9.26 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-08-01
CVE-2023-41955 WordPress Essential Addons for Elementor plugin <= 5.8.8 - Contributor+ Privilege Escalation vulnerability CWE-269 8.8 High2024-05-17
CVE-2023-32243 WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation CWE-287 9.8 Critical2023-05-12
CVE-2022-0320 Essential Addons for Elementor < 5.0.5 - Unauthenticated LFI CWE-22 9.8 -2022-02-01
CVE-2021-24255 Essential Addons for Elementor < 4.5.4 - Contributor+ Stored Cross-Site Scripting (XSS) CWE-79 5.4 -2021-05-05

All 16 known CVE vulnerabilities affecting Essential Addons for Elementor with full Chinese analysis, references, and POCs where available.