📦 The Plus Addons For Elementor

by Posimyth

🔍 What is The Plus Addons For Elementor?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-24949

CRITICAL CVSS 9.8 Jan 10, 2022

This vulnerability allows attackers to execute arbitrary SQL commands through the 'WP Search Filters' widget in The Plus Addons for Elementor Pro WordPress plugin. It affects WordPress sites using vul...

CVE-2021-24175

CRITICAL CVSS 9.8 Apr 5, 2021

This critical vulnerability in the Plus Addons for Elementor WordPress plugin allows unauthenticated attackers to bypass authentication completely. Attackers can log in as any user (including administ...

CVE-2024-5455

HIGH CVSS 8.8 Jun 21, 2024

This vulnerability in the Plus Addons for Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to perform Local File Inclusion via the 'magazine_style' par...

CVE-2023-47178

HIGH CVSS 8.6 May 17, 2024

This vulnerability allows unauthenticated attackers to perform path traversal attacks, enabling local file inclusion in WordPress sites using The Plus Addons for Elementor Pro plugin. Attackers can re...

CVE-2021-4331

HIGH CVSS 8.8 Mar 7, 2023

The Plus Addons for Elementor WordPress plugin allows privilege escalation through its registration form functionality. Users with access to Elementor page builder (like contributors) can set the defa...

CVE-2024-11829

MEDIUM CVSS 6.4 Feb 1, 2025

This vulnerability allows authenticated attackers with Contributor-level access or higher to inject malicious scripts into WordPress pages using the Table Widget in The Plus Addons for Elementor plugi...

CVE-2024-10365

MEDIUM CVSS 4.3 Nov 20, 2024

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to extract sensitive private, pending, and draft template data from the The Plus Addons for Elementor pl...

CVE-2024-8913

MEDIUM CVSS 4.3 Oct 11, 2024

This vulnerability in The Plus Addons for Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to extract sensitive private, pending, and draft template da...

CVE-2024-5583

MEDIUM CVSS 6.4 Aug 22, 2024

This stored XSS vulnerability in The Plus Addons for Elementor WordPress plugin allows authenticated attackers with contributor-level access or higher to inject malicious scripts into web pages. The s...

CVE-2024-5763

MEDIUM CVSS 6.4 Aug 20, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into website pages via the Video widget in The Plus Addons for Elementor plu...

CVE-2024-4482

MEDIUM CVSS 6.4 Jul 3, 2024

This vulnerability allows authenticated attackers with contributor-level access or higher to inject malicious scripts into WordPress pages using the The Plus Addons for Elementor plugin's Countdown wi...

CVE-2024-4983

MEDIUM CVSS 6.4 Jun 27, 2024

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into web pages using the The Plus Addons for Elementor plugin. When other us...

CVE-2024-5344

MEDIUM CVSS 6.1 Jun 21, 2024

This vulnerability allows unauthenticated attackers to perform reflected cross-site scripting (XSS) attacks via the 'forgoturl' parameter in The Plus Addons for Elementor plugin's WP Login & Register ...

CVE-2024-5341

MEDIUM CVSS 6.4 May 30, 2024

The Plus Addons for Elementor plugin for WordPress has a stored XSS vulnerability in the Heading Title widget's 'size' attribute. Authenticated attackers with contributor-level access or higher can in...

CVE-2024-4485

MEDIUM CVSS 6.4 May 24, 2024

This stored XSS vulnerability in The Plus Addons for Elementor WordPress plugin allows authenticated attackers with contributor-level permissions or higher to inject malicious scripts into website pag...

CVE-2024-2784

MEDIUM CVSS 6.4 May 24, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into web pages using the The Plus Addons for Elementor plugin's Hover Card w...

CVE-2024-2785

MEDIUM CVSS 6.4 May 14, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using the Age Gate widget in The Plus Addons for Elementor plugin...

CVE-2024-0445

MEDIUM CVSS 6.4 May 14, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using The Plus Addons for Elementor plugin. The scripts are store...

CVE-2024-3197

MEDIUM CVSS 6.4 May 2, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using The Plus Addons for Elementor plugin. The scripts execute w...