CVE-2026-28131
Addon Elements for Elementor (formerly Elementor Addon Elements)
Minimum safe version
1.14.5
Update to 1.14.5 or later to address 39 fixable vulnerabilities
CVE-2025-12537
CVE-2024-13215
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Elementor Addon Elements Plugin <= 1.13.8 is vulnerable to Sensitive Data Exposure
CVE-2024-47366
CVE-2024-47361
CVE-2024-7122
CVE-2024-4401
CVE-2024-4569
CVE-2024-4570
CVE-2024-2092
CVE-2024-3743
CVE-2024-30422
CVE-2024-2792
CVE-2024-2091
CVE-2024-29107
CVE-2024-1391
CVE-2024-1392
CVE-2024-1393
CVE-2024-1422
CVE-2024-1358
CVE-2024-0834
CVE-2023-5381
CVE-2023-4723
CVE-2023-4690
CVE-2023-4689
WordPress Elementor Addon Elements Plugin <= 1.11.16 is vulnerable to Cross Site Scripting (XSS)
Elementor Addon Elements <= 1.6.3 - Reflected Cross-Site Scripting
Elementor Addon Elements <= 1.11.7 - Cross-Site Request Forgery
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Elementor Addon Elements < 1.6.4 - CSRF & XSS
Elementor Addon Elements < 1.11.8 - CSRF Bypass
Unauthorised AJAX Calls via Freemius
WordPress Elementor Addon Elements plugin <= 1.6.3 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress Elementor Addon Elements plugin <= 1.11.1 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
WordPress Elementor Addon Elements plugin < 1.11.14 - Sensitive Information Disclosure vulnerability
WordPress Elementor Addon Elements plugin < 1.11.14 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2021-24259