CVE-2026-4362
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
Minimum safe version
3.9.0
Update to 3.9.0 or later to address 25 fixable vulnerabilities
ElementsKit Elementor Addons and Templates <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Simple Tab Widget
ElementsKit Elementor addons Lite < 3.7.9 - Missing Authorization
ElementsKit Elementor Addons and Templates <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget
ElementsKit Lite <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget
CVE-2024-11180
ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function
WordPress Elements kit Elementor addons Plugin <= 3.4.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-10091
CVE-2024-8546
CVE-2024-6455
CVE-2024-37255
CVE-2024-3650
CVE-2024-3499
CVE-2024-32505
CVE-2024-2803
CVE-2024-2047
CVE-2024-1238
CVE-2023-6525
CVE-2024-1239
CVE-2024-2042
CVE-2023-6582
CVE-2023-39993
WordPress Elements kit Elementor addons plugin <= 2.1.7 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
CVE-2021-24258