📦 Essential Addons For Elementor

by Wpdeveloper

🔍 What is Essential Addons For Elementor?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-32243

CRITICAL CVSS 9.8 May 12, 2023

This vulnerability allows unauthenticated attackers to reset passwords for any user account, including administrators, in WordPress sites using the Essential Addons for Elementor plugin. This affects ...

CVE-2022-0320

CRITICAL CVSS 9.8 Feb 1, 2022

This vulnerability in the Essential Addons for Elementor WordPress plugin allows unauthenticated attackers to perform Local File Inclusion attacks, reading arbitrary files on the server. It can lead t...

CVE-2024-8979

HIGH CVSS 8.0 Nov 15, 2024

The Essential Addons for Elementor WordPress plugin exposes sensitive user information through password reset email notifications. Authenticated attackers with Author-level access or higher can extrac...

CVE-2021-4447

HIGH CVSS 8.8 Oct 16, 2024

This vulnerability in the Essential Addons for Elementor WordPress plugin allows attackers with access to the Elementor page builder to create registration forms that default to administrator role, en...

CVE-2023-41955

HIGH CVSS 8.8 May 17, 2024

This vulnerability allows contributors on WordPress sites using Essential Addons for Elementor to escalate their privileges to administrator level. It affects all WordPress installations running Essen...

CVE-2024-3018

HIGH CVSS 8.8 Mar 30, 2024

This vulnerability in the Essential Addons for Elementor WordPress plugin allows authenticated attackers with author-level access or higher to perform PHP object injection via the 'error_resetpassword...

CVE-2024-1536

HIGH CVSS 7.4 Mar 13, 2024

This vulnerability allows authenticated WordPress users with contributor-level permissions or higher to inject malicious scripts into pages using the Essential Addons for Elementor plugin's event cale...

CVE-2023-32241

HIGH CVSS 7.1 Aug 29, 2023

This vulnerability allows unauthenticated attackers to inject malicious scripts into web pages via the WPDeveloper Essential Addons for Elementor Pro plugin. When users view pages containing the injec...

CVE-2025-69092

MEDIUM CVSS 6.5 Dec 30, 2025

This DOM-based XSS vulnerability in Essential Addons for Elementor allows attackers to inject malicious scripts into web pages viewed by users. It affects WordPress sites using the Essential Addons fo...

CVE-2024-9993

MEDIUM CVSS 6.4 Jun 7, 2025

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into website pages via the Event Calendar widget. The scripts execute whenev...

CVE-2025-39589

MEDIUM CVSS 4.3 Apr 16, 2025

This vulnerability in Essential Addons for Elementor WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retrieve embedded sensitive data from affected websites....

CVE-2024-56063

MEDIUM CVSS 6.5 Dec 31, 2024

This stored cross-site scripting (XSS) vulnerability in Essential Addons for Elementor allows attackers to inject malicious scripts into web pages that are then executed when other users view those pa...

CVE-2024-8978

MEDIUM CVSS 5.7 Nov 15, 2024

This vulnerability in the Essential Addons for Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to extract usernames and passwords of users who registe...

CVE-2024-8961

MEDIUM CVSS 6.4 Nov 15, 2024

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious JavaScript into website pages through the Essential Addons for Elementor plugin. The...

CVE-2024-8742

MEDIUM CVSS 6.4 Sep 13, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using the Filterable Gallery widget. The scripts are stored and e...

CVE-2024-8440

MEDIUM CVSS 6.4 Sep 11, 2024

This stored XSS vulnerability in Essential Addons for Elementor plugin allows authenticated attackers with contributor-level access or higher to inject malicious scripts via the Fancy Text widget. The...

CVE-2024-39649

MEDIUM CVSS 6.5 Aug 1, 2024

This stored cross-site scripting (XSS) vulnerability in the Essential Addons for Elementor WordPress plugin allows attackers to inject malicious scripts into web pages. When users view affected pages,...

CVE-2024-5188

MEDIUM CVSS 6.4 Jun 6, 2024

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into web pages via the Essential Addons for Elementor plugin. The scripts ex...

CVE-2024-4448

MEDIUM CVSS 6.5 May 14, 2024

This stored XSS vulnerability in the Essential Addons for Elementor WordPress plugin allows authenticated attackers with contributor-level access or higher to inject malicious scripts into web pages. ...

CVE-2024-4275

MEDIUM CVSS 6.4 May 14, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using the Interactive Circle widget. The scripts execute whenever...

CVE-2024-4156

MEDIUM CVSS 6.4 May 2, 2024

This stored XSS vulnerability in the Essential Addons for Elementor WordPress plugin allows authenticated attackers with contributor-level permissions or higher to inject malicious scripts into websit...

CVE-2024-4003

MEDIUM CVSS 6.4 May 2, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into web pages using the Essential Addons for Elementor plugin. The stored X...

CVE-2024-3728

MEDIUM CVSS 6.4 May 2, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into web pages using the Essential Addons for Elementor plugin's Filterable ...