VendorsPOSIMYTHthe_plus_addons_for_elementorall versions
Vulnerabilities

POSIMYTH Innovations The Plus Addons For Elementor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2021-24175
The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
Published 2021-04-05 · Modified
9.8EPSS 0.145
CVE-2021-24949
The Plus Addons for Elementor Pro < 5.0.7 - Unauthenticated SQL Injection
Published 2022-01-10 · Modified
9.8EPSS 0.017
CVE-2023-47178
WordPress The Plus Addons for Elementor Pro plugin <= 5.2.8 - Unauthenticated Local File Inclusion vulnerability
Published 2024-05-17 · Analyzed
9.8EPSS 0.006
CVE-2021-4331
The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege Escalation
Published 2023-03-07 · Modified
8.8EPSS 0.009
CVE-2024-5455
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.6 - Authenticated (Contributor+) Local File Inclusion
Published 2024-06-21 · Modified
8.8EPSS 0.006
CVE-2024-2203
The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Clients Widget
Published 2024-03-27 · Modified
8.8EPSS 0.006
CVE-2024-43932
WordPress The Plus Addons for Elementor plugin <= 5.6.2 - Broken Access Control vulnerability
Published 2024-11-01 · Modified
8.8EPSS 0.006
CVE-2021-24948
The Plus Addons for Elementor Pro < 5.0.7 - Sensitive Data Disclosure
Published 2022-01-10 · Modified
7.5EPSS 0.018
CVE-2021-4332
The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read
Published 2023-03-07 · Modified
6.5EPSS 0.008
CVE-2024-34373
WordPress The Plus Addons for Elementor plugin <= 5.4.2 - Cross Site Scripting (XSS) vulnerability
Published 2024-05-06 · Modified
6.5EPSS 0.003
CVE-2024-35709
WordPress The Plus Addons for Elementor plugin <= 5.5.4 - Cross Site Scripting (XSS) vulnerability
Published 2024-06-08 · Modified
6.5EPSS 0.003
CVE-2024-53823
WordPress The Plus Addons for Elementor plugin <= 5.6.14 - Cross Site Scripting (XSS) vulnerability
Published 2024-12-06 · Modified
6.5EPSS 0.003
CVE-2024-4484
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-05-24 · Modified
6.4EPSS 0.007
CVE-2024-0445
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-05-09 · Modified
6.4EPSS 0.005
CVE-2024-3199
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
Published 2024-05-02 · Modified
6.4EPSS 0.005
CVE-2024-2210
The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Team Member Listing
Published 2024-03-27 · Modified
6.4EPSS 0.005
CVE-2024-3197
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes
Published 2024-05-02 · Modified
6.4EPSS 0.004
CVE-2024-11829
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2025-02-01 · Analyzed
6.4EPSS 0.004
CVE-2024-4482
The Plus Addons for Elementor <= 5.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
Published 2024-07-03 · Modified
6.4EPSS 0.004
CVE-2024-3718
The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pricing Table, & Flip Box
Published 2024-05-24 · Modified
6.4EPSS 0.004
CVE-2024-5763
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget
Published 2024-08-20 · Analyzed
6.4EPSS 0.004
CVE-2024-4983
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.0- Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-06-27 · Modified
6.4EPSS 0.004
CVE-2024-1419
The Plus Addons for Elementor <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting Header Meta Content Widget
Published 2024-03-07 · Modified
6.4EPSS 0.003
CVE-2024-2785
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate
Published 2024-05-09 · Modified
6.4EPSS 0.003
CVE-2024-6575
The Plus Addons for Elementor <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via TP Page Scroll Widget
Published 2024-08-20 · Analyzed
6.4EPSS 0.003
CVE-2024-4485
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-05-24 · Modified
6.4EPSS 0.003
CVE-2025-1287
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
Published 2025-03-08 · Analyzed
6.4EPSS 0.003
CVE-2024-5341
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading Title Widget
Published 2024-05-30 · Modified
6.4EPSS 0.003
CVE-2024-2784
The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contibutor+) Stored Cross-Site Scripting via Hover Card
Published 2024-05-24 · Modified
6.4EPSS 0.003
CVE-2024-5583
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonials Widget Settings
Published 2024-08-22 · Analyzed
6.4EPSS 0.003
CVE-2021-24351
The Plus Addons for Elementor < 4.1.12 - Reflected Cross-Site Scripting (XSS)
Published 2021-06-14 · Modified
6.1EPSS 0.025
CVE-2021-24358
The Plus Addons for Elementor Page Builder < 4.1.10 - Open Redirect
Published 2021-06-14 · Modified
6.1EPSS 0.023
CVE-2024-5344
The Plus Addons for Elementor Page Builder <= 5.5.6 - Reflected Cross-Site Scripting via WP Login and Register Widget
Published 2024-06-21 · Modified
6.1EPSS 0.003
CVE-2024-43977
WordPress The Plus Addons for Elementor plugin <= 5.6.2 - Cross Site Scripting (XSS) vulnerability
Published 2024-09-17 · Modified
5.9EPSS 0.003
CVE-2021-24359
The Plus Addons for Elementor Page Builder < 4.1.11 - Arbitrary Reset Pwd Email Sending
Published 2021-06-14 · Modified
5.3EPSS 0.011
CVE-2024-8913
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_template
Published 2024-10-11 · Analyzed
4.3EPSS 0.004
CVE-2024-10365
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.0.3 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates
Published 2024-11-20 · Analyzed
4.3EPSS 0.003