Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Essential Addons for Elementor – Popular Elementor Templates & Widgets — Vulnerabilities & Security Advisories 48

All 48 CVE vulnerabilities found in Essential Addons for Elementor – Popular Elementor Templates & Widgets, with AI-generated Chinese analysis, references, and POCs.

This page documents security weaknesses associated with the Essential Addons for Elementor plugin, specifically focusing on vulnerabilities within its popular Elementor templates and widgets ecosystem. It aggregates known security issues, including remote code execution, privilege escalation, and information disclosure flaws, covering reported incidents from early 2021 through the present. This collection serves as a centralized resource for developers, security auditors, and site administrators to review the historical security posture of this widely used WordPress extension. By compiling data from official vendor advisories, third-party security databases, and community reports, the page provides a comprehensive timeline of disclosed defects. Users can track how the vendor responds to emerging threats, analyze patterns in specific weakness classes such as Cross-Site Scripting or improper input validation, and examine the evolution of security fixes for individual components. This information is critical for assessing risk levels and prioritizing updates in environments relying on this tool. Understanding the frequency and severity of past incidents helps in evaluating the robustness of the codebase and the effectiveness of the maintenance team. Readers can use this data to make informed decisions about whether to continue using the plugin, implement specific mitigations, or seek alternative solutions. The aggregated view highlights both critical and low-severity issues, offering a balanced perspective on the product’s security history. This transparency supports better decision-making for site owners concerned with compliance and protection against known exploitation vectors. Ultimately, the page aims to reduce uncertainty by providing clear, accessible records of all publicly disclosed vulnerabilities linked to the software.

Vendor: wpdevteam

CVE IDTitleCVSSSeverityPublished
CVE-2024-4003 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-20 6.4 Medium2024-05-02
CVE-2024-3733 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Information Exposure CWE-200 5.3 Medium2024-04-25
CVE-2024-3333 Essential Addons for Elementor <= 5.9.14 - Authenticated (Contributor+) Store Cross-Site Scripting via Widget URL Attribute CWE-79 6.4 Medium2024-04-17
CVE-2024-2623 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-04-09
CVE-2024-2974 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 - Unauthenticated Sensitive Information Exposure CWE-200 5.3 Medium2024-04-09
CVE-2024-2650 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-20 6.4 Medium2024-04-09
CVE-2024-3018 Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpassword CWE-502 8.8 High2024-03-30
CVE-2024-1537 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table CWE-79 6.4 Medium2024-03-13
CVE-2024-1536 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar CWE-79 7.4 High2024-03-13
CVE-2024-1171 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery CWE-79 5.4 Medium2024-02-20
CVE-2024-1172 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion CWE-79 5.4 Medium2024-02-20
CVE-2024-1276 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-20
CVE-2024-1236 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-20
CVE-2024-0586 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scritping CWE-79 6.4 Medium2024-02-05
CVE-2024-0954 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-05
CVE-2024-0585 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl CWE-79 5.4 Medium2024-02-05
CVE-2023-7044 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-01-04
CVE-2023-3779 Essential Addons For Elementor <=5.8.1 - Unauthenticated MailChimp API Key Disclosure CWE-200 5.3 Medium2023-07-20

All 48 known CVE vulnerabilities affecting Essential Addons for Elementor – Popular Elementor Templates & Widgets with full Chinese analysis, references, and POCs where available.